Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2234-1

Опубликовано: 03 июн. 2026
Источник: suse-cvrf

Описание

Security update for python-Pillow

This update for python-Pillow fixes the following issues

  • CVE-2026-42308: integer overflow in font processing can lead to denial of service (bsc#1265359).
  • CVE-2026-42310: infinite loop and resource exhaustion when processing specially crafted PDFs (bsc#1265154).

Список пакетов

SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Module for Python 3 15 SP7
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server 15 SP4-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server 15 SP5-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server 15 SP6-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1

Описание

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-Pillow-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-Pillow-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-Pillow-tk-9.5.0-150400.5.20.1

Ссылки

Описание

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.


Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-Pillow-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-Pillow-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-Pillow-tk-9.5.0-150400.5.20.1

Ссылки