Описание
Security update for python-Pillow
This update for python-Pillow fixes the following issue
- CVE-2026-42308: integer overflow in font processing can lead to denial of service (bsc#1265359).
Список пакетов
SUSE Linux Enterprise Module for Package Hub 15 SP7
python3-Pillow-7.2.0-150300.3.24.1
Ссылки
- Link for SUSE-SU-2026:2004-1
- E-Mail link for SUSE-SU-2026:2004-1
- SUSE Security Ratings
- SUSE Bug 1265359
- SUSE CVE CVE-2026-42308 page
Описание
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Затронутые продукты
SUSE Linux Enterprise Module for Package Hub 15 SP7:python3-Pillow-7.2.0-150300.3.24.1
Ссылки
- CVE-2026-42308
- SUSE Bug 1265359