Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:39127

Опубликовано: 15 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: python-pillow security update

Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.

Security Fix(es):

  • python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379)

  • python-pillow: Pillow: Denial of Service via crafted GD 2.x image file (CVE-2026-55380)

  • python-pillow: Pillow: Denial of Service via crafted PCF font data (CVE-2026-54059)

  • python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
python3-pillowx86_6422.el8_10python3-pillow-5.1.1-22.el8_10.x86_64.rpm

Показывать по

Связанные уязвимости

suse-cvrf
18 дней назад

Security update for python-Pillow

oracle-oval
18 дней назад

ELSA-2026-39127: python-pillow security update (IMPORTANT)

suse-cvrf
21 день назад

Security update for python-Pillow

CVSS3: 7.5
ubuntu
25 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.

CVSS3: 7.5
redhat
25 дней назад

Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.