<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:16:03.953956+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-pillow-2026-59199</id>
    <title>BIT-pillow-2026-59199 — Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow</title>
    <updated>2026-10-03T03:16:04.458531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-pillow-2026-59199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-59199</id>
    <title>BREW-aider-CVE-2026-59199 — Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow</title>
    <updated>2026-10-03T03:16:04.458620+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: aider</p>
<p>### Summary</p>
<p>Pillow's public image coordinate APIs can trigger a native heap out-of-bounds
write when given coordinates near the signed 32-bit integer limits. In 4-byte
pixel modes such as `RGBA`, this becomes a controlled backward heap underwrite:
for a source image of width `W`, Pillow writes `4 * W` attacker-controlled bytes
starting `4 * W` bytes before the destination row pointer. With successful large
image allocation, the theoretical upper bound is ~2 GiB backwards from
the destination row.</p>
<p>Minimal public API trigger:</p>
<p>```python
from PIL import Image</p>
<p>INT_MIN = -(1 &lt;&lt; 31)</p>
<p>src = Image.new("RGBA", (2, 1), (0x41, 0x42, 0x43, 0x44))
dst = Image.new("RGBA", (8, 1))
dst.paste(src, ((1 &lt;&lt; 31) - 2, 0, INT_MIN, 1))
```</p>
<p>The same root cause is also reachable through `Image.crop()` and
`Image.alpha_composite()`. No private API, ctypes, custom Python object, or
malformed image file is needed.</p>
<p>This has been confirmed as an ASAN heap-buffer-overflow write. On normal
non-ASAN Pillow builds, the minimal trigger corrupts the heap and aborts with
`double free or corruption (out)`</p>
<p>### Details</p>
<p>`src/PIL/Image.py:paste()` accepts a 4-tuple box and passes it to the native
`ImagingCore.paste()` method:</p>
<p>```python
self.im.paste(source, box)
```</p>
<p>`src/_imaging.c:_paste()` parses the four Python coordinates into signed `int`
values and calls `ImagingPaste()`:</p>
<p>```c
int x0, y0, x1, y1;
PyArg_ParseTuple(args, "O(iiii)|O!", &amp;source, &amp;x0, &amp;y0, &amp;x1, &amp;y1, ...);
status = ImagingPaste(self-&gt;image,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-59199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</id>
    <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
    <updated>2026-10-03T03:16:04.458691+00:00</updated>
    <content>certfr-2026-avi-1094</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-338027</id>
    <title>EUVD-2026-338027</title>
    <updated>2026-10-03T03:16:04.458732+00:00</updated>
    <content>EUVD-2026-338027</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-338027"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59199</id>
    <title>fkie_cve-2026-59199</title>
    <updated>2026-10-03T03:16:04.458746+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6r8x-57c9-28j4</id>
    <title>GHSA-6r8x-57c9-28j4 — Pillow: Heap out-of-bounds write `Image.paste()` / `Image.crop()` via signed coordinate overflow</title>
    <updated>2026-10-03T03:16:04.458782+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: Pillow</p>
<p>### Summary</p>
<p>Pillow's public image coordinate APIs can trigger a native heap out-of-bounds
write when given coordinates near the signed 32-bit integer limits. In 4-byte
pixel modes such as `RGBA`, this becomes a controlled backward heap underwrite:
for a source image of width `W`, Pillow writes `4 * W` attacker-controlled bytes
starting `4 * W` bytes before the destination row pointer. With successful large
image allocation, the theoretical upper bound is ~2 GiB backwards from
the destination row.</p>
<p>Minimal public API trigger:</p>
<p>```python
from PIL import Image</p>
<p>INT_MIN = -(1 &lt;&lt; 31)</p>
<p>src = Image.new("RGBA", (2, 1), (0x41, 0x42, 0x43, 0x44))
dst = Image.new("RGBA", (8, 1))
dst.paste(src, ((1 &lt;&lt; 31) - 2, 0, INT_MIN, 1))
```</p>
<p>The same root cause is also reachable through `Image.crop()` and
`Image.alpha_composite()`. No private API, ctypes, custom Python object, or
malformed image file is needed.</p>
<p>This has been confirmed as an ASAN heap-buffer-overflow write. On normal
non-ASAN Pillow builds, the minimal trigger corrupts the heap and aborts with
`double free or corruption (out)`</p>
<p>### Details</p>
<p>`src/PIL/Image.py:paste()` accepts a 4-tuple box and passes it to the native
`ImagingCore.paste()` method:</p>
<p>```python
self.im.paste(source, box)
```</p>
<p>`src/_imaging.c:_paste()` parses the four Python coordinates into signed `int`
values and calls `ImagingPaste()`:</p>
<p>```c
int x0, y0, x1, y1;
PyArg_ParseTuple(args, "O(iiii)|O!", &amp;source, &amp;x0, &amp;y0, &amp;x1, &amp;y1, ...);
status = ImagingPaste(self-&gt;image,…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6r8x-57c9-28j4"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-3185</id>
    <title>OESA-2026-3185 — python-pillow security update</title>
    <updated>2026-10-03T03:16:04.458846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: python-pillow</p>
<p>Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)

Security Fix(es):</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.(CVE-2026-54058)</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;apos;s public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.(CVE-2026-59197)</p>
<p>Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;apos;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.(CVE-2026-59198)</p>
<p>Pillow is a Python imaging library. Prior to 12.3.…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-3185"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21544-1</id>
    <title>openSUSE-SU-2026:21544-1 — Security update for python-Pillow</title>
    <updated>2026-10-03T03:16:04.458882+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Pillow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:21544-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-3451</id>
    <title>PYSEC-2026-3451</title>
    <updated>2026-10-03T03:16:04.458904+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-3451"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:48933</id>
    <title>RHSA-2026:48933 — Red Hat Security Advisory: Red Hat Quay 3.15.7</title>
    <updated>2026-10-03T03:16:04.458923+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity decode-uri-component: decode-uri-component: Denial of Service via crafted input Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file Pillow: Pillow: Native heap out-of-bounds write Pillow: Pillow: Denial of Service via out-of-bounds write in image processing Pillow: Pillow: Denial of service via crafted PDF stream Pillow: Pillow: Denial of Service via crafted JPEG2000 image Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:48933"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1</id>
    <title>SUSE-SU-2026:23217-1 — Security update for python-Pillow</title>
    <updated>2026-10-03T03:16:04.458959+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for python-Pillow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59199</id>
    <title>UBUNTU-CVE-2026-59199</title>
    <updated>2026-10-03T03:16:04.458976+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:Pro:18.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow</p>
<p>Pillow is a Python imaging library. Prior to 12.3.0, Pillow public image coordinate APIs can trigger a native heap out-of-bounds write when given coordinates near the signed 32-bit integer limits in Image.paste(), Image.crop(), or Image.alpha_composite(). This issue is fixed in version 12.3.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59199"/>
  </entry>
</feed>
