gpp_maybe
Security update for python-pillow
SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2875
This update for python-Pillow fixes the following issues - CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). - CVE-2026-54060: a font can trigger excessive allocation during conversion or saving (bsc#1270410). - CVE-2026-55379: bypass of decompression bomb protection, allowing excessive memory allocation (bsc#1270411). - CVE-2026-55380: crafted .gd file can trigger excessive C-heap allocation when loaded (bsc#1270412).
-
Release DateJul 13 2026
-
ReferencesBugzilla: 1270409, 1270410, 1270411, 1270412
CVEs: CVE-2026-54059, CVE-2026-54060, CVE-2026-55379, CVE-2026-55380 -
Typesecurity
-
Severityimportant
cloud_download Downloads
To download packages, you need to log in and have a valid subscription.
SUSE Package Hub 15.7 s390x
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.27.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.27.1 lock rpm
SUSE Package Hub 15.7 aarch64
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.27.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.27.1 lock rpm
SUSE Package Hub 15.7 ppc64le
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.27.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.27.1 lock rpm
SUSE Package Hub 15.7 x86_64
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.27.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.27.1 lock rpm