Количество 8
Количество 8
GHSA-xj96-63gp-2gmr
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
CVE-2026-59197
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.
CVE-2026-59197
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.
CVE-2026-59197
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.
CVE-2026-59197
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public r ...
ELSA-2026-48021
ELSA-2026-48021: python-pillow security update (IMPORTANT)
SUSE-SU-2026:3084-1
Security update for python-Pillow
SUSE-SU-2026:3268-1
Security update for python-Pillow
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xj96-63gp-2gmr Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` | CVSS3: 8.2 | 0% Низкий | 14 дней назад | |
CVE-2026-59197 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0. | CVSS3: 8.2 | 0% Низкий | 20 дней назад | |
CVE-2026-59197 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0. | CVSS3: 8.2 | 0% Низкий | 20 дней назад | |
CVE-2026-59197 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0. | CVSS3: 8.2 | 0% Низкий | 20 дней назад | |
CVE-2026-59197 Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public r ... | CVSS3: 8.2 | 0% Низкий | 20 дней назад | |
ELSA-2026-48021 ELSA-2026-48021: python-pillow security update (IMPORTANT) | 5 дней назад | |||
SUSE-SU-2026:3084-1 Security update for python-Pillow | 18 дней назад | |||
SUSE-SU-2026:3268-1 Security update for python-Pillow | 8 дней назад |
Уязвимостей на страницу