<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T14:25:56.481927+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:48021</id>
    <title>ALSA-2026:48021 — Important: python-pillow security update</title>
    <updated>2026-10-02T14:25:57.235246+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: python3-pillow, AlmaLinux:8: python3-pillow-devel, AlmaLinux:8: python3-pillow-doc, AlmaLinux:8: python3-pillow-tk</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
  * Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:48021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-11288</id>
    <title>bdu:2026-11288</title>
    <updated>2026-10-02T14:25:57.235400+00:00</updated>
    <content>bdu:2026-11288</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-11288"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-pillow-2026-59197</id>
    <title>BIT-pillow-2026-59197 — Pillow: Heap out-of-bounds write in Pillow `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`</title>
    <updated>2026-10-02T14:25:57.235429+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-pillow-2026-59197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-59197</id>
    <title>BREW-aider-CVE-2026-59197 — Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`</title>
    <updated>2026-10-02T14:25:57.235471+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>### Summary</p>
<p>Pillow's public rank-filter API can trigger a native heap out-of-bounds write
when given a very large odd filter size.</p>
<p>Minimal public API trigger:</p>
<p>```python
from PIL import Image, ImageFilter</p>
<p>im = Image.new("L", (3, 3), 128)
im.filter(ImageFilter.MedianFilter(4294967295))
```</p>
<p>`ImageFilter.RankFilter.filter()` calls `image.expand(size // 2, size // 2)`
before rank-filter size validation. With `size = 4294967295`, the
expansion margin is `2147483647` (`INT_MAX`). `ImagingExpand()` then computes
the output dimensions with unchecked signed `int` arithmetic. On tested builds,
this wraps to a tiny output image and the border-expansion loop writes past the
allocation.</p>
<p>This is reachable through documented public classes (`RankFilter`,
`MedianFilter`, `MinFilter`, and `MaxFilter`). No private API, ctypes, or custom
Python object is needed.</p>
<p>### Details</p>
<p>Current `src/PIL/ImageFilter.py`:</p>
<p>```python
class RankFilter(Filter):
    def filter(self, image):
        if image.mode == "P":
            msg = "cannot filter palette images"
            raise ValueError(msg)
        image = image.expand(self.size // 2, self.size // 2)
        return image.rankfilter(self.size, self.rank)
```</p>
<p>The `expand()` call is made before `image.rankfilter(...)`.</p>
<p>Current `src/libImaging/Filter.c:ImagingExpand()` does not check output-size
overflow:</p>
<p>```c
if (xmargin &lt; 0 &amp;&amp; ymargin &lt; 0) {
    return (Imaging)ImagingError_ValueError("bad kernel size");
}</p>
<p>imOut = ImagingNewDirty(
    imIn-&gt;m…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-59197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-02T14:25:57.235582+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-339264</id>
    <title>EUVD-2026-339264</title>
    <updated>2026-10-02T14:25:57.235614+00:00</updated>
    <content>EUVD-2026-339264</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-339264"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59197</id>
    <title>fkie_cve-2026-59197</title>
    <updated>2026-10-02T14:25:57.235636+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xj96-63gp-2gmr</id>
    <title>GHSA-xj96-63gp-2gmr — Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`</title>
    <updated>2026-10-02T14:25:57.235675+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Pillow</p>
<p>### Summary</p>
<p>Pillow's public rank-filter API can trigger a native heap out-of-bounds write
when given a very large odd filter size.</p>
<p>Minimal public API trigger:</p>
<p>```python
from PIL import Image, ImageFilter</p>
<p>im = Image.new("L", (3, 3), 128)
im.filter(ImageFilter.MedianFilter(4294967295))
```</p>
<p>`ImageFilter.RankFilter.filter()` calls `image.expand(size // 2, size // 2)`
before rank-filter size validation. With `size = 4294967295`, the
expansion margin is `2147483647` (`INT_MAX`). `ImagingExpand()` then computes
the output dimensions with unchecked signed `int` arithmetic. On tested builds,
this wraps to a tiny output image and the border-expansion loop writes past the
allocation.</p>
<p>This is reachable through documented public classes (`RankFilter`,
`MedianFilter`, `MinFilter`, and `MaxFilter`). No private API, ctypes, or custom
Python object is needed.</p>
<p>### Details</p>
<p>Current `src/PIL/ImageFilter.py`:</p>
<p>```python
class RankFilter(Filter):
    def filter(self, image):
        if image.mode == "P":
            msg = "cannot filter palette images"
            raise ValueError(msg)
        image = image.expand(self.size // 2, self.size // 2)
        return image.rankfilter(self.size, self.rank)
```</p>
<p>The `expand()` call is made before `image.rankfilter(...)`.</p>
<p>Current `src/libImaging/Filter.c:ImagingExpand()` does not check output-size
overflow:</p>
<p>```c
if (xmargin &lt; 0 &amp;&amp; ymargin &lt; 0) {
    return (Imaging)ImagingError_ValueError("bad kernel size");
}</p>
<p>imOut = ImagingNewDirty(
    imIn-&gt;m…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xj96-63gp-2gmr"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3137</id>
    <title>OESA-2026-3137 — python-pillow security update</title>
    <updated>2026-10-02T14:25:57.235766+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: python-pillow</p>
<p>Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)

Security Fix(es):</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-54059)</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(&amp;quot;1&amp;quot;, (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.(CVE-2026-54060)</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow&amp;apos;s documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-55379)</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimen…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3137"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21544-1</id>
    <title>openSUSE-SU-2026:21544-1 — Security update for python-Pillow</title>
    <updated>2026-10-02T14:25:57.235855+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Pillow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21544-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3454</id>
    <title>PYSEC-2026-3454</title>
    <updated>2026-10-02T14:25:57.235891+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3454"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48933</id>
    <title>RHSA-2026:48933 — Red Hat Security Advisory: Red Hat Quay 3.15.7</title>
    <updated>2026-10-02T14:25:57.235935+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity decode-uri-component: decode-uri-component: Denial of Service via crafted input Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file Pillow: Pillow: Native heap out-of-bounds write Pillow: Pillow: Denial of Service via out-of-bounds write in image processing Pillow: Pillow: Denial of service via crafted PDF stream Pillow: Pillow: Denial of Service via crafted JPEG2000 image Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2026:48021</id>
    <title>RLSA-2026:48021 — Important: python-pillow security update</title>
    <updated>2026-10-02T14:25:57.236000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: python-pillow</p>
<p>Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.</p>
<p>Security Fix(es):</p>
<p>* Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)</p>
<p>* Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2026:48021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1</id>
    <title>SUSE-SU-2026:23217-1 — Security update for python-Pillow</title>
    <updated>2026-10-02T14:25:57.236043+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Pillow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59197</id>
    <title>UBUNTU-CVE-2026-59197</title>
    <updated>2026-10-02T14:25:57.236072+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:Pro:18.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59197"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2592</id>
    <title>WID-SEC-W-2026-2592 — Red Hat Enterprise Linux (Pillow): Mehrere Schwachstellen</title>
    <updated>2026-10-02T14:25:57.236128+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (Pillow) ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, und um Daten zu manipulieren.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2592"/>
  </entry>
</feed>
