<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 04:05:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:48021 — Important: python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:48021</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-pillow, AlmaLinux:8: python3-pillow-devel, AlmaLinux:8: python3-pillow-doc, AlmaLinux:8: python3-pillow-tk&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
  * Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: python3-pillow, AlmaLinux:8: python3-pillow-devel, AlmaLinux:8: python3-pillow-doc, AlmaLinux:8: python3-pillow-tk&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
  * Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:48021</guid>
    </item>
    <item>
      <title>bdu:2026-09900</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09900</link>
      <description>bdu:2026-09900</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09900</guid>
    </item>
    <item>
      <title>BIT-pillow-2026-54058 — Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)</title>
      <link>https://cve.radiocsirt.org/vuln/bit-pillow-2026-54058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-pillow-2026-54058</guid>
    </item>
    <item>
      <title>BREW-aider-CVE-2026-54058 — Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-54058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image&amp;#39;s row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-row spacing (`stride`) is taken from the tile arguments. `map.c` validates `offset + ysize*stride &amp;lt;= buffer_len` but **never checks that `stride` is at least the natural row width `xsize * pixelsize`**.&lt;/p&gt;
&lt;p&gt;The **McIdas** AREA plugin (`McIdasImagePlugin.py`) derives `stride`, `offset`, `xsize`, and `ysize` directly from attacker-controlled 32-bit header words with no validation. By supplying a `stride` far smaller than the row width, an attacker makes each row pointer read `xsize*pixelsize` bytes that run past the mapped region. Accessing the pixels (e.g. `Image.tobytes()`,
`getpixel`, `convert`, `save`) then reads adjacent process memory (information disclosure) or faults (SIGBUS, denial of service).&lt;/p&gt;
&lt;p&gt;## Complete Code Trace&lt;/p&gt;
&lt;p&gt;**Step 1: `McIdasImageFile._open`** - turns attacker header words into image size, file offset, and row stride with no validation.&lt;/p&gt;
&lt;p&gt;```python
# src/PIL/McIdasImagePlugin.py:41-70
s = self.fp.read(256)
if not _accept(s) or len(s) != 256:        # _accept: prefix == b&amp;#34;\x00\x00\x00\x00\x00\x00\x00\x04&amp;#34;
    raise SyntaxError(...)
self.area_descriptor = w = [0, *struct.unpack(&amp;#34;!64i&amp;#34;, s)]   # w[1..64] = signed BE int32, ALL attacker-controlled&lt;/p&gt;
&lt;p&gt;if w[11] == 1:
    mode…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image&amp;#39;s row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-row spacing (`stride`) is taken from the tile arguments. `map.c` validates `offset + ysize*stride &amp;lt;= buffer_len` but **never checks that `stride` is at least the natural row width `xsize * pixelsize`**.&lt;/p&gt;
&lt;p&gt;The **McIdas** AREA plugin (`McIdasImagePlugin.py`) derives `stride`, `offset`, `xsize`, and `ysize` directly from attacker-controlled 32-bit header words with no validation. By supplying a `stride` far smaller than the row width, an attacker makes each row pointer read `xsize*pixelsize` bytes that run past the mapped region. Accessing the pixels (e.g. `Image.tobytes()`,
`getpixel`, `convert`, `save`) then reads adjacent process memory (information disclosure) or faults (SIGBUS, denial of service).&lt;/p&gt;
&lt;p&gt;## Complete Code Trace&lt;/p&gt;
&lt;p&gt;**Step 1: `McIdasImageFile._open`** - turns attacker header words into image size, file offset, and row stride with no validation.&lt;/p&gt;
&lt;p&gt;```python
# src/PIL/McIdasImagePlugin.py:41-70
s = self.fp.read(256)
if not _accept(s) or len(s) != 256:        # _accept: prefix == b&amp;#34;\x00\x00\x00\x00\x00\x00\x00\x04&amp;#34;
    raise SyntaxError(...)
self.area_descriptor = w = [0, *struct.unpack(&amp;#34;!64i&amp;#34;, s)]   # w[1..64] = signed BE int32, ALL attacker-controlled&lt;/p&gt;
&lt;p&gt;if w[11] == 1:
    mode…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-54058</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>EUVD-2026-336639</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336639</link>
      <description>EUVD-2026-336639</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336639</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54058</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54058</link>
      <description>&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54058</guid>
    </item>
    <item>
      <title>GHSA-62p4-gmf7-7g93 — Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-62p4-gmf7-7g93</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image&amp;#39;s row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-row spacing (`stride`) is taken from the tile arguments. `map.c` validates `offset + ysize*stride &amp;lt;= buffer_len` but **never checks that `stride` is at least the natural row width `xsize * pixelsize`**.&lt;/p&gt;
&lt;p&gt;The **McIdas** AREA plugin (`McIdasImagePlugin.py`) derives `stride`, `offset`, `xsize`, and `ysize` directly from attacker-controlled 32-bit header words with no validation. By supplying a `stride` far smaller than the row width, an attacker makes each row pointer read `xsize*pixelsize` bytes that run past the mapped region. Accessing the pixels (e.g. `Image.tobytes()`,
`getpixel`, `convert`, `save`) then reads adjacent process memory (information disclosure) or faults (SIGBUS, denial of service).&lt;/p&gt;
&lt;p&gt;## Complete Code Trace&lt;/p&gt;
&lt;p&gt;**Step 1: `McIdasImageFile._open`** - turns attacker header words into image size, file offset, and row stride with no validation.&lt;/p&gt;
&lt;p&gt;```python
# src/PIL/McIdasImagePlugin.py:41-70
s = self.fp.read(256)
if not _accept(s) or len(s) != 256:        # _accept: prefix == b&amp;#34;\x00\x00\x00\x00\x00\x00\x00\x04&amp;#34;
    raise SyntaxError(...)
self.area_descriptor = w = [0, *struct.unpack(&amp;#34;!64i&amp;#34;, s)]   # w[1..64] = signed BE int32, ALL attacker-controlled&lt;/p&gt;
&lt;p&gt;if w[11] == 1:
    mode…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image&amp;#39;s row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-row spacing (`stride`) is taken from the tile arguments. `map.c` validates `offset + ysize*stride &amp;lt;= buffer_len` but **never checks that `stride` is at least the natural row width `xsize * pixelsize`**.&lt;/p&gt;
&lt;p&gt;The **McIdas** AREA plugin (`McIdasImagePlugin.py`) derives `stride`, `offset`, `xsize`, and `ysize` directly from attacker-controlled 32-bit header words with no validation. By supplying a `stride` far smaller than the row width, an attacker makes each row pointer read `xsize*pixelsize` bytes that run past the mapped region. Accessing the pixels (e.g. `Image.tobytes()`,
`getpixel`, `convert`, `save`) then reads adjacent process memory (information disclosure) or faults (SIGBUS, denial of service).&lt;/p&gt;
&lt;p&gt;## Complete Code Trace&lt;/p&gt;
&lt;p&gt;**Step 1: `McIdasImageFile._open`** - turns attacker header words into image size, file offset, and row stride with no validation.&lt;/p&gt;
&lt;p&gt;```python
# src/PIL/McIdasImagePlugin.py:41-70
s = self.fp.read(256)
if not _accept(s) or len(s) != 256:        # _accept: prefix == b&amp;#34;\x00\x00\x00\x00\x00\x00\x00\x04&amp;#34;
    raise SyntaxError(...)
self.area_descriptor = w = [0, *struct.unpack(&amp;#34;!64i&amp;#34;, s)]   # w[1..64] = signed BE int32, ALL attacker-controlled&lt;/p&gt;
&lt;p&gt;if w[11] == 1:
    mode…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-62p4-gmf7-7g93</guid>
    </item>
    <item>
      <title>OESA-2026-3185 — python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3185</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.(CVE-2026-54058)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;amp;apos;s public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.(CVE-2026-59197)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;amp;apos;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.(CVE-2026-59198)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.(CVE-2026-54058)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;amp;apos;s public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.(CVE-2026-59197)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;amp;apos;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.(CVE-2026-59198)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3185</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11283-1 — python313-Pillow-12.3.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11283-1</link>
      <description>&lt;p&gt;python313-Pillow-12.3.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-Pillow-12.3.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11283-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3493 — Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3493</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image&amp;#39;s row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-row spacing (`stride`) is taken from the tile arguments. `map.c` validates `offset + ysize*stride &amp;lt;= buffer_len` but **never checks that `stride` is at least the natural row width `xsize * pixelsize`**.&lt;/p&gt;
&lt;p&gt;The **McIdas** AREA plugin (`McIdasImagePlugin.py`) derives `stride`, `offset`, `xsize`, and `ysize` directly from attacker-controlled 32-bit header words with no validation. By supplying a `stride` far smaller than the row width, an attacker makes each row pointer read `xsize*pixelsize` bytes that run past the mapped region. Accessing the pixels (e.g. `Image.tobytes()`,
`getpixel`, `convert`, `save`) then reads adjacent process memory (information disclosure) or faults (SIGBUS, denial of service).&lt;/p&gt;
&lt;p&gt;## Complete Code Trace&lt;/p&gt;
&lt;p&gt;**Step 1: `McIdasImageFile._open`** - turns attacker header words into image size, file offset, and row stride with no validation.&lt;/p&gt;
&lt;p&gt;```python
# src/PIL/McIdasImagePlugin.py:41-70
s = self.fp.read(256)
if not _accept(s) or len(s) != 256:        # _accept: prefix == b&amp;#34;\x00\x00\x00\x00\x00\x00\x00\x04&amp;#34;
    raise SyntaxError(...)
self.area_descriptor = w = [0, *struct.unpack(&amp;#34;!64i&amp;#34;, s)]   # w[1..64] = signed BE int32, ALL attacker-controlled&lt;/p&gt;
&lt;p&gt;if w[11] == 1:
    mode…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;When Pillow loads an uncompressed image whose tile uses the `raw` codec and a mode in `Image._MAPMODES`, and the image was opened **from a filename**, it memory-maps the file and builds the image&amp;#39;s row pointers directly into the mapping via `PyImaging_MapBuffer` (`src/map.c`). The per-row spacing (`stride`) is taken from the tile arguments. `map.c` validates `offset + ysize*stride &amp;lt;= buffer_len` but **never checks that `stride` is at least the natural row width `xsize * pixelsize`**.&lt;/p&gt;
&lt;p&gt;The **McIdas** AREA plugin (`McIdasImagePlugin.py`) derives `stride`, `offset`, `xsize`, and `ysize` directly from attacker-controlled 32-bit header words with no validation. By supplying a `stride` far smaller than the row width, an attacker makes each row pointer read `xsize*pixelsize` bytes that run past the mapped region. Accessing the pixels (e.g. `Image.tobytes()`,
`getpixel`, `convert`, `save`) then reads adjacent process memory (information disclosure) or faults (SIGBUS, denial of service).&lt;/p&gt;
&lt;p&gt;## Complete Code Trace&lt;/p&gt;
&lt;p&gt;**Step 1: `McIdasImageFile._open`** - turns attacker header words into image size, file offset, and row stride with no validation.&lt;/p&gt;
&lt;p&gt;```python
# src/PIL/McIdasImagePlugin.py:41-70
s = self.fp.read(256)
if not _accept(s) or len(s) != 256:        # _accept: prefix == b&amp;#34;\x00\x00\x00\x00\x00\x00\x00\x04&amp;#34;
    raise SyntaxError(...)
self.area_descriptor = w = [0, *struct.unpack(&amp;#34;!64i&amp;#34;, s)]   # w[1..64] = signed BE int32, ALL attacker-controlled&lt;/p&gt;
&lt;p&gt;if w[11] == 1:
    mode…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3493</guid>
    </item>
    <item>
      <title>RHSA-2026:48933 — Red Hat Security Advisory: Red Hat Quay 3.15.7</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:48933</link>
      <description>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity decode-uri-component: decode-uri-component: Denial of Service via crafted input Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file Pillow: Pillow: Native heap out-of-bounds write Pillow: Pillow: Denial of Service via out-of-bounds write in image processing Pillow: Pillow: Denial of service via crafted PDF stream Pillow: Pillow: Denial of Service via crafted JPEG2000 image Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity decode-uri-component: decode-uri-component: Denial of Service via crafted input Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file Pillow: Pillow: Native heap out-of-bounds write Pillow: Pillow: Denial of Service via out-of-bounds write in image processing Pillow: Pillow: Denial of service via crafted PDF stream Pillow: Pillow: Denial of Service via crafted JPEG2000 image Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:48933</guid>
    </item>
    <item>
      <title>RLSA-2026:48021 — Important: python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/rlsa-2026:48021</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: python-pillow&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)&lt;/p&gt;
&lt;p&gt;* Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Rocky Linux:8: python-pillow&lt;/p&gt;
&lt;p&gt;Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)&lt;/p&gt;
&lt;p&gt;* Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rlsa-2026:48021</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23217-1 — Security update for python-Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1</link>
      <description>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-54058</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54058</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:Pro:18.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:Pro:18.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-54058</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2592 — Red Hat Enterprise Linux (Pillow): Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2592</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (Pillow) ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, und um Daten zu manipulieren.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux (Pillow) ausnutzen, um Informationen offenzulegen, um einen Denial of Service Angriff durchzuführen, und um Daten zu manipulieren.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2592</guid>
    </item>
  </channel>
</rss>
