{"id":"OESA-2026-3139","summary":"python-pillow security update","details":"Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \\ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)\r\n\r\nSecurity Fix(es):\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-54059)\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(&quot;1&quot;, (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.(CVE-2026-54060)\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow&apos;s documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-55379)\n\nPillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimensions from the GD 2.x header and stored them in self._size without calling Image._decompression_bomb_check(), allowing a crafted .gd file to trigger excessive C-heap allocation when loaded. This issue is fixed in version 12.3.0.(CVE-2026-55380)\n\nPillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser.PdfStream.decode() in PIL/PdfParser.py calls zlib.decompress() with bufsize set to the PDF stream Length field without bounding the decompressed output size, allowing a crafted FlateDecode PDF stream to exhaust memory from a small file. This issue is fixed in version 12.3.0.(CVE-2026-59200)\n\nPillow is a Python imaging library. From 8.2.0 through 12.2.0, src/libImaging/Jpeg2KDecode.c accumulates total_component_width across every tile in a JPEG2000 image instead of recomputing it per tile, allowing a crafted tiled JPEG2000 file to force substantially higher transient memory usage and trigger out-of-memory failures during decoding. This issue is fixed in version 12.3.0.(CVE-2026-59204)","modified":"2026-07-24T03:45:16.343787995Z","published":"2026-07-24T03:27:21Z","upstream":["CVE-2026-54059","CVE-2026-54060","CVE-2026-55379","CVE-2026-55380","CVE-2026-59200","CVE-2026-59204"],"database_specific":{"severity":"High"},"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3139"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54059"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54060"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55379"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55380"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59200"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59204"}],"affected":[{"package":{"name":"python-pillow","ecosystem":"openEuler:24.03-LTS-SP1","purl":"pkg:rpm/openEuler/python-pillow&distro=openEuler-24.03-LTS-SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"10.3.0-8.oe2403sp1"}]}],"ecosystem_specific":{"x86_64":["python-pillow-debuginfo-10.3.0-8.oe2403sp1.x86_64.rpm","python-pillow-debugsource-10.3.0-8.oe2403sp1.x86_64.rpm","python3-pillow-10.3.0-8.oe2403sp1.x86_64.rpm","python3-pillow-devel-10.3.0-8.oe2403sp1.x86_64.rpm","python3-pillow-qt-10.3.0-8.oe2403sp1.x86_64.rpm","python3-pillow-tk-10.3.0-8.oe2403sp1.x86_64.rpm"],"aarch64":["python-pillow-debuginfo-10.3.0-8.oe2403sp1.aarch64.rpm","python-pillow-debugsource-10.3.0-8.oe2403sp1.aarch64.rpm","python3-pillow-10.3.0-8.oe2403sp1.aarch64.rpm","python3-pillow-devel-10.3.0-8.oe2403sp1.aarch64.rpm","python3-pillow-qt-10.3.0-8.oe2403sp1.aarch64.rpm","python3-pillow-tk-10.3.0-8.oe2403sp1.aarch64.rpm"],"noarch":["python3-pillow-help-10.3.0-8.oe2403sp1.noarch.rpm"],"src":["python-pillow-10.3.0-8.oe2403sp1.src.rpm"]},"database_specific":{"source":"https://repo.openeuler.org/security/data/osv/OESA-2026-3139.json"}}],"schema_version":"1.7.5"}