Описание
Security update for python-Pillow
This update for python-Pillow fixes the following issues
- CVE-2026-42308: integer overflow in font processing can lead to denial of service (bsc#1265359).
- CVE-2026-42310: infinite loop and resource exhaustion when processing specially crafted PDFs (bsc#1265154).
Список пакетов
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Module for Python 3 15 SP7
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server 15 SP4-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server 15 SP5-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server 15 SP6-LTSS
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
python311-Pillow-9.5.0-150400.5.20.1
python311-Pillow-tk-9.5.0-150400.5.20.1
Ссылки
- Link for SUSE-SU-2026:2234-1
- E-Mail link for SUSE-SU-2026:2234-1
- SUSE Security Ratings
- SUSE Bug 1265154
- SUSE Bug 1265359
- SUSE CVE CVE-2026-42308 page
- SUSE CVE CVE-2026-42310 page
Описание
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-Pillow-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-Pillow-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-Pillow-tk-9.5.0-150400.5.20.1
Ссылки
- CVE-2026-42308
- SUSE Bug 1265359
Описание
Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0.
Затронутые продукты
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-Pillow-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS:python311-Pillow-tk-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-Pillow-9.5.0-150400.5.20.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS:python311-Pillow-tk-9.5.0-150400.5.20.1
Ссылки
- CVE-2026-42310
- SUSE Bug 1265154