Описание
ELSA-2026-39127: python-pillow security update (IMPORTANT)
[5.1.1-22]
- Security fix for CVE-2026-54059, CVE-2026-54060, CVE-2026-55379, CVE-2026-55380 Resolves: RHEL-192830, RHEL-192770, RHEL-192684, RHEL-192731
Обновленные пакеты
Oracle Linux 8
Oracle Linux aarch64
python3-pillow-devel
5.1.1-22.el8_10
python3-pillow-doc
5.1.1-22.el8_10
python3-pillow-tk
5.1.1-22.el8_10
python3-pillow
5.1.1-22.el8_10
Oracle Linux x86_64
python3-pillow
5.1.1-22.el8_10
python3-pillow-devel
5.1.1-22.el8_10
python3-pillow-doc
5.1.1-22.el8_10
python3-pillow-tk
5.1.1-22.el8_10
Связанные уязвимости
CVSS3: 7.5
ubuntu
25 дней назад
Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.