shield
Security update for python-pillow
SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3084
This update for python-Pillow fixes the following issues - CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). - CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). - CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). - CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). - CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). - CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). - CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch
-
Release DateJul 16 2026
-
ReferencesBugzilla: 1271418, 1271419, 1271420, 1271421, 1271422, 1271424, 1271425
CVEs: CVE-2026-54058, CVE-2026-59197, CVE-2026-59198, CVE-2026-59199, CVE-2026-59200, CVE-2026-59204, CVE-2026-59205 -
Typesecurity
-
Severitymoderate
cloud_download Downloads
SUSE Package Hub 15.7 s390x
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.30.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.30.1 lock rpm
SUSE Package Hub 15.7 aarch64
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.30.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.30.1 lock rpm
SUSE Package Hub 15.7 ppc64le
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.30.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.30.1 lock rpm
SUSE Package Hub 15.7 x86_64
-
Packagespython-Pillow
Python Imaging Library (Fork)python3-Pillow7.2.0-150300.3.30.1 lock src
Python Imaging Library (Fork)7.2.0-150300.3.30.1 lock rpm