Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-48021

Опубликовано: 30 июл. 2026
Источник: oracle-oval
Платформа: Oracle Linux 8

Описание

ELSA-2026-48021: python-pillow security update (IMPORTANT)

[5.1.1-23]

  • Security fix for CVE-2026-54058, CVE-2026-59197 Resolves: RHEL-211857, RHEL-211848

Обновленные пакеты

Oracle Linux 8

Oracle Linux aarch64

python3-pillow-devel

5.1.1-23.el8_10

python3-pillow-doc

5.1.1-23.el8_10

python3-pillow-tk

5.1.1-23.el8_10

python3-pillow

5.1.1-23.el8_10

Oracle Linux x86_64

python3-pillow

5.1.1-23.el8_10

python3-pillow-devel

5.1.1-23.el8_10

python3-pillow-doc

5.1.1-23.el8_10

python3-pillow-tk

5.1.1-23.el8_10

Связанные CVE

Связанные уязвимости

suse-cvrf
18 дней назад

Security update for python-Pillow

suse-cvrf
8 дней назад

Security update for python-Pillow

CVSS3: 8.2
ubuntu
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

CVSS3: 8.2
redhat
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

CVSS3: 8.2
nvd
20 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.