{"schema_version":"1.9.0","id":"openSUSE-SU-2026:21544-1","published":"2026-08-10T17:36:28Z","modified":"2026-08-12T18:23:41.374022335Z","related":["CVE-2026-54058","CVE-2026-59197","CVE-2026-59198","CVE-2026-59199","CVE-2026-59200","CVE-2026-59204","CVE-2026-59205"],"upstream":["CVE-2026-54058","CVE-2026-59197","CVE-2026-59198","CVE-2026-59199","CVE-2026-59200","CVE-2026-59204","CVE-2026-59205"],"summary":"Security update for python-Pillow","details":"This update for python-Pillow fixes the following issues\n\n- CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419).\n- CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`\n  (bsc#1271418).\n- CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420).\n- CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow\n  (bsc#1271421).\n- CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422).\n- CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424).\n- CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch\n  (bsc#1271425).\n","affected":[{"package":{"name":"python-Pillow","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"11.3.0-160000.8.1"}]}],"ecosystem_specific":{"binaries":[{"python313-Pillow":"11.3.0-160000.8.1","python313-Pillow-tk":"11.3.0-160000.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21544-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271418"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271419"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271420"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271421"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271422"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271424"},{"type":"REPORT","url":"https://bugzilla.suse.com/1271425"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54058"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59198"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59200"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59204"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59205"}]}