Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42311

Опубликовано: 09 мая 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

A flaw was found in Pillow, a Python imaging library. An attacker could exploit this vulnerability by tricking a user into processing a specially crafted malicious PSD file. This could lead to memory corruption, potentially causing the application to crash or allowing for arbitrary code execution.

Отчет

This is an Important severity flaw in Pillow, a Python imaging library, that could lead to arbitrary code execution. The vulnerability requires a user to process a specially crafted malicious PSD file, which could result in memory corruption and allow an attacker to execute arbitrary code. Red Hat products that process untrusted image files using Pillow are at risk if they do not adequately sanitize input or operate in a sandboxed environment.

Меры по смягчению последствий

To mitigate this vulnerability, users should avoid processing untrusted or suspicious PSD image files with applications that utilize the Pillow library. Implementing strict input validation and sanitization for image uploads and processing workflows can reduce the risk. Additionally, running applications that process untrusted content within a sandboxed environment can limit the potential impact of successful exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Affected
Lightspeed Corelightspeed-core/lightspeed-stack-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-service-api-rhel9Affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Will not fix
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Will not fix
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2468459Pillow: python-pillow: Pillow: Arbitrary code execution via malicious PSD file processing

EPSS

Процентиль: 5%
0.0015
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

CVSS3: 7.8
nvd
3 месяца назад

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0.

CVSS3: 7.8
debian
3 месяца назад

Pillow is a Python imaging library. From version 10.3.0 to before vers ...

CVSS3: 8.4
redos
20 дней назад

Уязвимость python-pillow

github
3 месяца назад

Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)

EPSS

Процентиль: 5%
0.0015
Низкий

7.8 High

CVSS3

Уязвимость CVE-2026-42311