<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 02:44:26 +0000</lastBuildDate>
    <item>
      <title>BIT-pillow-2026-59205 — Pillow: Controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch</title>
      <link>https://cve.radiocsirt.org/vuln/bit-pillow-2026-59205</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;#39;s ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform&amp;#39;s declared output mode. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;#39;s ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform&amp;#39;s declared output mode. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-pillow-2026-59205</guid>
    </item>
    <item>
      <title>BREW-aider-CVE-2026-59205 — Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch</title>
      <link>https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-59205</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger
controlled native heap corruption when the caller supplies an output image whose
mode does not match the transform&amp;#39;s declared output mode.&lt;/p&gt;
&lt;p&gt;For example, a transform built as `RGBA -&amp;gt; RGBA` can be applied to an `L` output
image. Pillow checks dimensions only, then calls LittleCMS with the output row
pointer. LittleCMS writes RGBA-sized rows into a 1-byte-per-pixel `L` image row.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/ImageCms.py:ImageCmsTransform.apply()` accepts an optional caller
supplied `imOut`:&lt;/p&gt;
&lt;p&gt;```python
def apply(self, im, imOut=None):
    if imOut is None:
        imOut = Image.new(self.output_mode, im.size, None)
    self.transform.apply(im.getim(), imOut.getim())
    imOut.info[&amp;#34;icc_profile&amp;#34;] = self.output_profile.tobytes()
    return imOut
```&lt;/p&gt;
&lt;p&gt;If `imOut` is provided, Pillow does not check:&lt;/p&gt;
&lt;p&gt;```text
im.mode == self.input_mode
imOut.mode == self.output_mode
```&lt;/p&gt;
&lt;p&gt;The C wrapper in `src/_imagingcms.c` unwraps both image cores and only checks
that the output dimensions are at least as large as the input dimensions:&lt;/p&gt;
&lt;p&gt;```c
static int
pyCMSdoTransform(Imaging im, Imaging imOut, cmsHTRANSFORM hTransform) {
    if (im-&amp;gt;xsize &amp;gt; imOut-&amp;gt;xsize || im-&amp;gt;ysize &amp;gt; imOut-&amp;gt;ysize) {
        return -1;
    }&lt;/p&gt;
&lt;p&gt;for (i = 0; i &amp;lt; im-&amp;gt;ysize; i++) {
        cmsDoTransform(hTransform, im-&amp;gt;image[i], imOut-&amp;gt;image[i], im-&amp;gt;xsize);
    }&lt;/p&gt;
&lt;p&gt;pyCMScopyAux(hTransform, imOut, im);
    return 0;
}
```&lt;/p&gt;
&lt;p&gt;`findLCMStype()` maps `R…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: aider&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger
controlled native heap corruption when the caller supplies an output image whose
mode does not match the transform&amp;#39;s declared output mode.&lt;/p&gt;
&lt;p&gt;For example, a transform built as `RGBA -&amp;gt; RGBA` can be applied to an `L` output
image. Pillow checks dimensions only, then calls LittleCMS with the output row
pointer. LittleCMS writes RGBA-sized rows into a 1-byte-per-pixel `L` image row.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/ImageCms.py:ImageCmsTransform.apply()` accepts an optional caller
supplied `imOut`:&lt;/p&gt;
&lt;p&gt;```python
def apply(self, im, imOut=None):
    if imOut is None:
        imOut = Image.new(self.output_mode, im.size, None)
    self.transform.apply(im.getim(), imOut.getim())
    imOut.info[&amp;#34;icc_profile&amp;#34;] = self.output_profile.tobytes()
    return imOut
```&lt;/p&gt;
&lt;p&gt;If `imOut` is provided, Pillow does not check:&lt;/p&gt;
&lt;p&gt;```text
im.mode == self.input_mode
imOut.mode == self.output_mode
```&lt;/p&gt;
&lt;p&gt;The C wrapper in `src/_imagingcms.c` unwraps both image cores and only checks
that the output dimensions are at least as large as the input dimensions:&lt;/p&gt;
&lt;p&gt;```c
static int
pyCMSdoTransform(Imaging im, Imaging imOut, cmsHTRANSFORM hTransform) {
    if (im-&amp;gt;xsize &amp;gt; imOut-&amp;gt;xsize || im-&amp;gt;ysize &amp;gt; imOut-&amp;gt;ysize) {
        return -1;
    }&lt;/p&gt;
&lt;p&gt;for (i = 0; i &amp;lt; im-&amp;gt;ysize; i++) {
        cmsDoTransform(hTransform, im-&amp;gt;image[i], imOut-&amp;gt;image[i], im-&amp;gt;xsize);
    }&lt;/p&gt;
&lt;p&gt;pyCMScopyAux(hTransform, imOut, im);
    return 0;
}
```&lt;/p&gt;
&lt;p&gt;`findLCMStype()` maps `R…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-aider-cve-2026-59205</guid>
    </item>
    <item>
      <title>certfr-2026-avi-1094 — De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquan…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</link>
      <description>certfr-2026-avi-1094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-1094</guid>
    </item>
    <item>
      <title>EUVD-2026-336635</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-336635</link>
      <description>EUVD-2026-336635</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-336635</guid>
    </item>
    <item>
      <title>fkie_cve-2026-59205</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59205</link>
      <description>&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;#39;s ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform&amp;#39;s declared output mode. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;#39;s ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform&amp;#39;s declared output mode. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-59205</guid>
    </item>
    <item>
      <title>GHSA-9hw9-ch79-4vh6 — Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-9hw9-ch79-4vh6</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger
controlled native heap corruption when the caller supplies an output image whose
mode does not match the transform&amp;#39;s declared output mode.&lt;/p&gt;
&lt;p&gt;For example, a transform built as `RGBA -&amp;gt; RGBA` can be applied to an `L` output
image. Pillow checks dimensions only, then calls LittleCMS with the output row
pointer. LittleCMS writes RGBA-sized rows into a 1-byte-per-pixel `L` image row.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/ImageCms.py:ImageCmsTransform.apply()` accepts an optional caller
supplied `imOut`:&lt;/p&gt;
&lt;p&gt;```python
def apply(self, im, imOut=None):
    if imOut is None:
        imOut = Image.new(self.output_mode, im.size, None)
    self.transform.apply(im.getim(), imOut.getim())
    imOut.info[&amp;#34;icc_profile&amp;#34;] = self.output_profile.tobytes()
    return imOut
```&lt;/p&gt;
&lt;p&gt;If `imOut` is provided, Pillow does not check:&lt;/p&gt;
&lt;p&gt;```text
im.mode == self.input_mode
imOut.mode == self.output_mode
```&lt;/p&gt;
&lt;p&gt;The C wrapper in `src/_imagingcms.c` unwraps both image cores and only checks
that the output dimensions are at least as large as the input dimensions:&lt;/p&gt;
&lt;p&gt;```c
static int
pyCMSdoTransform(Imaging im, Imaging imOut, cmsHTRANSFORM hTransform) {
    if (im-&amp;gt;xsize &amp;gt; imOut-&amp;gt;xsize || im-&amp;gt;ysize &amp;gt; imOut-&amp;gt;ysize) {
        return -1;
    }&lt;/p&gt;
&lt;p&gt;for (i = 0; i &amp;lt; im-&amp;gt;ysize; i++) {
        cmsDoTransform(hTransform, im-&amp;gt;image[i], imOut-&amp;gt;image[i], im-&amp;gt;xsize);
    }&lt;/p&gt;
&lt;p&gt;pyCMScopyAux(hTransform, imOut, im);
    return 0;
}
```&lt;/p&gt;
&lt;p&gt;`findLCMStype()` maps `R…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;Pillow&amp;#39;s public `ImageCms.ImageCmsTransform.apply(im, imOut)` API can trigger
controlled native heap corruption when the caller supplies an output image whose
mode does not match the transform&amp;#39;s declared output mode.&lt;/p&gt;
&lt;p&gt;For example, a transform built as `RGBA -&amp;gt; RGBA` can be applied to an `L` output
image. Pillow checks dimensions only, then calls LittleCMS with the output row
pointer. LittleCMS writes RGBA-sized rows into a 1-byte-per-pixel `L` image row.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;`src/PIL/ImageCms.py:ImageCmsTransform.apply()` accepts an optional caller
supplied `imOut`:&lt;/p&gt;
&lt;p&gt;```python
def apply(self, im, imOut=None):
    if imOut is None:
        imOut = Image.new(self.output_mode, im.size, None)
    self.transform.apply(im.getim(), imOut.getim())
    imOut.info[&amp;#34;icc_profile&amp;#34;] = self.output_profile.tobytes()
    return imOut
```&lt;/p&gt;
&lt;p&gt;If `imOut` is provided, Pillow does not check:&lt;/p&gt;
&lt;p&gt;```text
im.mode == self.input_mode
imOut.mode == self.output_mode
```&lt;/p&gt;
&lt;p&gt;The C wrapper in `src/_imagingcms.c` unwraps both image cores and only checks
that the output dimensions are at least as large as the input dimensions:&lt;/p&gt;
&lt;p&gt;```c
static int
pyCMSdoTransform(Imaging im, Imaging imOut, cmsHTRANSFORM hTransform) {
    if (im-&amp;gt;xsize &amp;gt; imOut-&amp;gt;xsize || im-&amp;gt;ysize &amp;gt; imOut-&amp;gt;ysize) {
        return -1;
    }&lt;/p&gt;
&lt;p&gt;for (i = 0; i &amp;lt; im-&amp;gt;ysize; i++) {
        cmsDoTransform(hTransform, im-&amp;gt;image[i], imOut-&amp;gt;image[i], im-&amp;gt;xsize);
    }&lt;/p&gt;
&lt;p&gt;pyCMScopyAux(hTransform, imOut, im);
    return 0;
}
```&lt;/p&gt;
&lt;p&gt;`findLCMStype()` maps `R…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-9hw9-ch79-4vh6</guid>
    </item>
    <item>
      <title>OESA-2026-3185 — python-pillow security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3185</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.(CVE-2026-54058)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;amp;apos;s public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.(CVE-2026-59197)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;amp;apos;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.(CVE-2026-59198)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: python-pillow&lt;/p&gt;
&lt;p&gt;Pillow is the friendly PIL fork by Alex Clark and Contributors. PIL is the Python Imaging \ Library by Fredrik Lundh and Contributors. As of 2019, Pillow development is supported by Tidelift.    of CVE-2022-22815,CVE-2022-22816)&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.(CVE-2026-54058)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;amp;apos;s public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.(CVE-2026-59197)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow&amp;amp;apos;s TGA RLE encoder reads past its packed row buffer when saving a mode 1 image with TGA RLE compression, allowing adjacent process heap bytes to be copied into the generated TGA file. This issue is fixed in version 12.3.0.(CVE-2026-59198)&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3185</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:21544-1 — Security update for python-Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:21544-1</link>
      <description>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:21544-1</guid>
    </item>
    <item>
      <title>PYSEC-2026-3453</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-3453</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;#39;s ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform&amp;#39;s declared output mode. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;#39;s ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform&amp;#39;s declared output mode. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-3453</guid>
    </item>
    <item>
      <title>RHSA-2026:48933 — Red Hat Security Advisory: Red Hat Quay 3.15.7</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:48933</link>
      <description>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity decode-uri-component: decode-uri-component: Denial of Service via crafted input Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file Pillow: Pillow: Native heap out-of-bounds write Pillow: Pillow: Denial of Service via out-of-bounds write in image processing Pillow: Pillow: Denial of service via crafted PDF stream Pillow: Pillow: Denial of Service via crafted JPEG2000 image Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity decode-uri-component: decode-uri-component: Denial of Service via crafted input Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files python-pillow: Pillow: Denial of Service via crafted BDF font file python-pillow: Pillow: Denial of Service via crafted GD 2.x image file Pillow: Pillow: Native heap out-of-bounds write Pillow: Pillow: Denial of Service via out-of-bounds write in image processing Pillow: Pillow: Denial of service via crafted PDF stream Pillow: Pillow: Denial of Service via crafted JPEG2000 image Pillow: Pillow: Controlled native heap corruption in ImageCms.ImageCmsTransform.apply API pyasn1: python-pyasn1: pyasn1: Denial of Service via crafted ASN.1 OBJECT IDENTIFIER pyasn1: pyasn1: Denial of Service via crafted ASN.1 REAL values&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:48933</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23217-1 — Security update for python-Pillow</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1</link>
      <description>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for python-Pillow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23217-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-59205</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59205</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:Pro:18.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;#39;s ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform&amp;#39;s declared output mode. This issue is fixed in version 12.3.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: pillow, Ubuntu:Pro:16.04:LTS: pillow, Ubuntu:Pro:18.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow, Ubuntu:Pro:20.04:LTS: pillow-python2, Ubuntu:22.04:LTS: pillow, Ubuntu:24.04:LTS: pillow, Ubuntu:26.04:LTS: pillow&lt;/p&gt;
&lt;p&gt;Pillow is a Python imaging library. Prior to 12.3.0, Pillow&amp;#39;s ImageCms.ImageCmsTransform.apply(im, imOut) API can trigger controlled native heap corruption when the caller supplies an output image whose mode does not match the transform&amp;#39;s declared output mode. This issue is fixed in version 12.3.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-59205</guid>
    </item>
  </channel>
</rss>
