{"schema_version":"1.7.5","id":"SUSE-SU-2026:3268-1","published":"2026-07-27T10:59:25Z","modified":"2026-07-28T10:00:08.428650372Z","related":["CVE-2026-54058","CVE-2026-54059","CVE-2026-54060","CVE-2026-55379","CVE-2026-55380","CVE-2026-59197","CVE-2026-59198","CVE-2026-59199","CVE-2026-59200","CVE-2026-59204","CVE-2026-59205"],"upstream":["CVE-2026-54058","CVE-2026-54059","CVE-2026-54060","CVE-2026-55379","CVE-2026-55380","CVE-2026-59197","CVE-2026-59198","CVE-2026-59199","CVE-2026-59200","CVE-2026-59204","CVE-2026-59205"],"summary":"Security update for python-Pillow","details":"This update for python-Pillow fixes the following issues:\n\n- CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419).\n- CVE-2026-54059: bomb protection bypass via PCF font loading due to `Image.frombytes()` being called without\n  `_decompression_bomb_check()` (bsc#1270409).\n- CVE-2026-54060: excessive allocation due to `FontFile.compile()`: `Image.new()` being called without\n  `_decompression_bomb_check()` (bsc#1270410).\n- CVE-2026-55379: bomb protection bypass via font loading due to `Image.new()` being called without\n  `_decompression_bomb_check()` (bsc#1270411).\n- CVE-2026-55380: unchecked 4.3 GB C-heap allocation due to image dimensions being accepted without\n  `_decompression_bomb_check()` in `GdImageFile._open()` (bsc#1270412).  \n- CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`\n  (bsc#1271418).\n- CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420).\n- CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow\n  (bsc#1271421).\n- CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422).\n- CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424).\n- CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch\n  (bsc#1271425).\n","affected":[{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise Module for Python 3 15 SP7","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Python%203%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}},{"package":{"name":"python-Pillow","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0-150400.5.25.1"}]}],"ecosystem_specific":{"binaries":[{"python311-Pillow":"9.5.0-150400.5.25.1","python311-Pillow-tk":"9.5.0-150400.5.25.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3268-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263268-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270409"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270410"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270411"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270412"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271419"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271420"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271421"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271422"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271424"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271425"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54058"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54059"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54060"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55379"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55380"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59198"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59200"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59205"}]}