<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 21:45:47 +0000</lastBuildDate>
    <item>
      <title>bdu:2026-09899</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-09899</link>
      <description>bdu:2026-09899</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-09899</guid>
    </item>
    <item>
      <title>BIT-pillow-2026-59198 — Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images</title>
      <link>https://cve.radiocsirt.org/vuln/bit-pillow-2026-59198</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;#39;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;#39;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-pillow-2026-59198</guid>
    </item>
    <item>
      <title>BREW-aider-CVE-2026-59198 — Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-59198</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s TGA RLE encoder reads past its row buffer when saving a mode `&amp;#34;1&amp;#34;`
image. Adjacent process heap bytes can be copied into the generated TGA file.&lt;/p&gt;
&lt;p&gt;The bug is reachable through the public save API:&lt;/p&gt;
&lt;p&gt;```python
im.save(out, format=&amp;#34;TGA&amp;#34;, compression=&amp;#34;tga_rle&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;Older affected Pillow versions use the equivalent public option `rle=True`.&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, Pillow allocates a packed row buffer of `ceil(width / 8)`
bytes, but `ImagingTgaRleEncode()` treats the row as one full byte per pixel.&lt;/p&gt;
&lt;p&gt;The maximum valid TGA width is `65535`. At that width:&lt;/p&gt;
&lt;p&gt;```text
allocated packed row buffer: 8192 bytes
encoder byte-offset walk:     65535 bytes
maximum OOB window per row:   57343 bytes
```&lt;/p&gt;
&lt;p&gt;On non-ASAN Pillow `12.2.0`, the public-only maximum-width PoC below serialized
`57297` bytes from distinct out-of-bounds source offsets into one returned TGA,
covering `99.92%` of the maximum adjacent heap window. No heap grooming, ctypes,
private API, or malformed input file was used. The disclosure is emitted across
many TGA packet payload copies of at most `128` bytes each, not one large
`memcpy()`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/TgaImagePlugin.py` allows mode `&amp;#34;1&amp;#34;` TGA output and selects the
`tga_rle` encoder when RLE compression is requested.&lt;/p&gt;
&lt;p&gt;`src/encode.c:_setimage()` allocates the row buffer using the packed-bit
formula:&lt;/p&gt;
&lt;p&gt;```c
state-&amp;gt;bytes = (state-&amp;gt;bits * state-&amp;gt;xsize + 7) / 8;
state-&amp;gt;buffer = (UINT8 *)calloc(1, state-&amp;gt;bytes);
```&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, `state-&amp;gt;bits == 1`.&lt;/p&gt;
&lt;p&gt;`src/libIma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s TGA RLE encoder reads past its row buffer when saving a mode `&amp;#34;1&amp;#34;`
image. Adjacent process heap bytes can be copied into the generated TGA file.&lt;/p&gt;
&lt;p&gt;The bug is reachable through the public save API:&lt;/p&gt;
&lt;p&gt;```python
im.save(out, format=&amp;#34;TGA&amp;#34;, compression=&amp;#34;tga_rle&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;Older affected Pillow versions use the equivalent public option `rle=True`.&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, Pillow allocates a packed row buffer of `ceil(width / 8)`
bytes, but `ImagingTgaRleEncode()` treats the row as one full byte per pixel.&lt;/p&gt;
&lt;p&gt;The maximum valid TGA width is `65535`. At that width:&lt;/p&gt;
&lt;p&gt;```text
allocated packed row buffer: 8192 bytes
encoder byte-offset walk:     65535 bytes
maximum OOB window per row:   57343 bytes
```&lt;/p&gt;
&lt;p&gt;On non-ASAN Pillow `12.2.0`, the public-only maximum-width PoC below serialized
`57297` bytes from distinct out-of-bounds source offsets into one returned TGA,
covering `99.92%` of the maximum adjacent heap window. No heap grooming, ctypes,
private API, or malformed input file was used. The disclosure is emitted across
many TGA packet payload copies of at most `128` bytes each, not one large
`memcpy()`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/TgaImagePlugin.py` allows mode `&amp;#34;1&amp;#34;` TGA output and selects the
`tga_rle` encoder when RLE compression is requested.&lt;/p&gt;
&lt;p&gt;`src/encode.c:_setimage()` allocates the row buffer using the packed-bit
formula:&lt;/p&gt;
&lt;p&gt;```c
state-&amp;gt;bytes = (state-&amp;gt;bits * state-&amp;gt;xsize + 7) / 8;
state-&amp;gt;buffer = (UINT8 *)calloc(1, state-&amp;gt;bytes);
```&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, `state-&amp;gt;bits == 1`.&lt;/p&gt;
&lt;p&gt;`src/libIma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-59198</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>EUVD-2026-336752</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336752</link>
      <description>EUVD-2026-336752</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336752</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59198</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59198</link>
      <description>&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;#39;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;#39;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59198</guid>
    </item>
    <item>
      <title>GHSA-fj7v-r99m-22gq — Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fj7v-r99m-22gq</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Pillow&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s TGA RLE encoder reads past its row buffer when saving a mode `&amp;#34;1&amp;#34;`
image. Adjacent process heap bytes can be copied into the generated TGA file.&lt;/p&gt;
&lt;p&gt;The bug is reachable through the public save API:&lt;/p&gt;
&lt;p&gt;```python
im.save(out, format=&amp;#34;TGA&amp;#34;, compression=&amp;#34;tga_rle&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;Older affected Pillow versions use the equivalent public option `rle=True`.&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, Pillow allocates a packed row buffer of `ceil(width / 8)`
bytes, but `ImagingTgaRleEncode()` treats the row as one full byte per pixel.&lt;/p&gt;
&lt;p&gt;The maximum valid TGA width is `65535`. At that width:&lt;/p&gt;
&lt;p&gt;```text
allocated packed row buffer: 8192 bytes
encoder byte-offset walk:     65535 bytes
maximum OOB window per row:   57343 bytes
```&lt;/p&gt;
&lt;p&gt;On non-ASAN Pillow `12.2.0`, the public-only maximum-width PoC below serialized
`57297` bytes from distinct out-of-bounds source offsets into one returned TGA,
covering `99.92%` of the maximum adjacent heap window. No heap grooming, ctypes,
private API, or malformed input file was used. The disclosure is emitted across
many TGA packet payload copies of at most `128` bytes each, not one large
`memcpy()`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/TgaImagePlugin.py` allows mode `&amp;#34;1&amp;#34;` TGA output and selects the
`tga_rle` encoder when RLE compression is requested.&lt;/p&gt;
&lt;p&gt;`src/encode.c:_setimage()` allocates the row buffer using the packed-bit
formula:&lt;/p&gt;
&lt;p&gt;```c
state-&amp;gt;bytes = (state-&amp;gt;bits * state-&amp;gt;xsize + 7) / 8;
state-&amp;gt;buffer = (UINT8 *)calloc(1, state-&amp;gt;bytes);
```&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, `state-&amp;gt;bits == 1`.&lt;/p&gt;
&lt;p&gt;`src/libIma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: Pillow&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s TGA RLE encoder reads past its row buffer when saving a mode `&amp;#34;1&amp;#34;`
image. Adjacent process heap bytes can be copied into the generated TGA file.&lt;/p&gt;
&lt;p&gt;The bug is reachable through the public save API:&lt;/p&gt;
&lt;p&gt;```python
im.save(out, format=&amp;#34;TGA&amp;#34;, compression=&amp;#34;tga_rle&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;Older affected Pillow versions use the equivalent public option `rle=True`.&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, Pillow allocates a packed row buffer of `ceil(width / 8)`
bytes, but `ImagingTgaRleEncode()` treats the row as one full byte per pixel.&lt;/p&gt;
&lt;p&gt;The maximum valid TGA width is `65535`. At that width:&lt;/p&gt;
&lt;p&gt;```text
allocated packed row buffer: 8192 bytes
encoder byte-offset walk:     65535 bytes
maximum OOB window per row:   57343 bytes
```&lt;/p&gt;
&lt;p&gt;On non-ASAN Pillow `12.2.0`, the public-only maximum-width PoC below serialized
`57297` bytes from distinct out-of-bounds source offsets into one returned TGA,
covering `99.92%` of the maximum adjacent heap window. No heap grooming, ctypes,
private API, or malformed input file was used. The disclosure is emitted across
many TGA packet payload copies of at most `128` bytes each, not one large
`memcpy()`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/TgaImagePlugin.py` allows mode `&amp;#34;1&amp;#34;` TGA output and selects the
`tga_rle` encoder when RLE compression is requested.&lt;/p&gt;
&lt;p&gt;`src/encode.c:_setimage()` allocates the row buffer using the packed-bit
formula:&lt;/p&gt;
&lt;p&gt;```c
state-&amp;gt;bytes = (state-&amp;gt;bits * state-&amp;gt;xsize + 7) / 8;
state-&amp;gt;buffer = (UINT8 *)calloc(1, state-&amp;gt;bytes);
```&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, `state-&amp;gt;bits == 1`.&lt;/p&gt;
&lt;p&gt;`src/libIma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fj7v-r99m-22gq</guid>
    </item>
    <item>
      <title>OESA-2026-3141 — python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3141</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-54059)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(&amp;amp;quot;1&amp;amp;quot;, (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.(CVE-2026-54060)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow&amp;amp;apos;s documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-55379)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimen…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP4: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, PIL/PcfFontFile.py _load_bitmaps() read glyph dimensions from the PCF METRICS section and passed them directly to Image.frombytes() without calling Image._decompression_bomb_check(), allowing crafted PCF font data to cause excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-54059)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, PIL/FontFile.py FontFile.compile() assembled per-glyph images into a combined bitmap with Image.new(&amp;amp;quot;1&amp;amp;quot;, (xsize, ysize)) without calling Image._decompression_bomb_check(), allowing a font to trigger excessive allocation during conversion or saving. This issue is fixed in version 12.3.0.(CVE-2026-54060)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow&amp;amp;apos;s documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0.(CVE-2026-55379)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, PIL/GdImageFile.py GdImageFile._open() read image dimen…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3141</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11283-1 — python313-Pillow-12.3.0-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11283-1</link>
      <description>&lt;p&gt;python313-Pillow-12.3.0-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;python313-Pillow-12.3.0-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11283-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3494 — Pillow TGA RLE encoder can serialize up to ~57 KB of adjacent heap data into generated images</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3494</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s TGA RLE encoder reads past its row buffer when saving a mode `&amp;#34;1&amp;#34;`
image. Adjacent process heap bytes can be copied into the generated TGA file.&lt;/p&gt;
&lt;p&gt;The bug is reachable through the public save API:&lt;/p&gt;
&lt;p&gt;```python
im.save(out, format=&amp;#34;TGA&amp;#34;, compression=&amp;#34;tga_rle&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;Older affected Pillow versions use the equivalent public option `rle=True`.&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, Pillow allocates a packed row buffer of `ceil(width / 8)`
bytes, but `ImagingTgaRleEncode()` treats the row as one full byte per pixel.&lt;/p&gt;
&lt;p&gt;The maximum valid TGA width is `65535`. At that width:&lt;/p&gt;
&lt;p&gt;```text
allocated packed row buffer: 8192 bytes
encoder byte-offset walk:     65535 bytes
maximum OOB window per row:   57343 bytes
```&lt;/p&gt;
&lt;p&gt;On non-ASAN Pillow `12.2.0`, the public-only maximum-width PoC below serialized
`57297` bytes from distinct out-of-bounds source offsets into one returned TGA,
covering `99.92%` of the maximum adjacent heap window. No heap grooming, ctypes,
private API, or malformed input file was used. The disclosure is emitted across
many TGA packet payload copies of at most `128` bytes each, not one large
`memcpy()`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/TgaImagePlugin.py` allows mode `&amp;#34;1&amp;#34;` TGA output and selects the
`tga_rle` encoder when RLE compression is requested.&lt;/p&gt;
&lt;p&gt;`src/encode.c:_setimage()` allocates the row buffer using the packed-bit
formula:&lt;/p&gt;
&lt;p&gt;```c
state-&amp;gt;bytes = (state-&amp;gt;bits * state-&amp;gt;xsize + 7) / 8;
state-&amp;gt;buffer = (UINT8 *)calloc(1, state-&amp;gt;bytes);
```&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, `state-&amp;gt;bits == 1`.&lt;/p&gt;
&lt;p&gt;`src/libIma…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s TGA RLE encoder reads past its row buffer when saving a mode `&amp;#34;1&amp;#34;`
image. Adjacent process heap bytes can be copied into the generated TGA file.&lt;/p&gt;
&lt;p&gt;The bug is reachable through the public save API:&lt;/p&gt;
&lt;p&gt;```python
im.save(out, format=&amp;#34;TGA&amp;#34;, compression=&amp;#34;tga_rle&amp;#34;)
```&lt;/p&gt;
&lt;p&gt;Older affected Pillow versions use the equivalent public option `rle=True`.&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, Pillow allocates a packed row buffer of `ceil(width / 8)`
bytes, but `ImagingTgaRleEncode()` treats the row as one full byte per pixel.&lt;/p&gt;
&lt;p&gt;The maximum valid TGA width is `65535`. At that width:&lt;/p&gt;
&lt;p&gt;```text
allocated packed row buffer: 8192 bytes
encoder byte-offset walk:     65535 bytes
maximum OOB window per row:   57343 bytes
```&lt;/p&gt;
&lt;p&gt;On non-ASAN Pillow `12.2.0`, the public-only maximum-width PoC below serialized
`57297` bytes from distinct out-of-bounds source offsets into one returned TGA,
covering `99.92%` of the maximum adjacent heap window. No heap grooming, ctypes,
private API, or malformed input file was used. The disclosure is emitted across
many TGA packet payload copies of at most `128` bytes each, not one large
`memcpy()`.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/TgaImagePlugin.py` allows mode `&amp;#34;1&amp;#34;` TGA output and selects the
`tga_rle` encoder when RLE compression is requested.&lt;/p&gt;
&lt;p&gt;`src/encode.c:_setimage()` allocates the row buffer using the packed-bit
formula:&lt;/p&gt;
&lt;p&gt;```c
state-&amp;gt;bytes = (state-&amp;gt;bits * state-&amp;gt;xsize + 7) / 8;
state-&amp;gt;buffer = (UINT8 *)calloc(1, state-&amp;gt;bytes);
```&lt;/p&gt;
&lt;p&gt;For mode `&amp;#34;1&amp;#34;`, `state-&amp;gt;bits == 1`.&lt;/p&gt;
&lt;p&gt;`src/libIma…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3494</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23217-1 — Security update for python-Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1</link>
      <description>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59198</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59198</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;#39;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;#39;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59198</guid>
    </item>
  </channel>
</rss>
