Security update for python-Pillow
This update for python-Pillow fixes the following issues - CVE-2026-42311: malicious PSD file processing can lead to arbitrary code execution (bsc#1270404). - CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). - CVE-2026-54060: fonts can trigger excessive memory allocation during conversion or saving (bsc#1270410). - CVE-2026-55379: bypass of decompression bomb protection allows excessive memory allocation (bsc#1270411). - CVE-2026-55380: crafted `.gd` file can trigger excessive C-heap allocation when loaded (bsc#1270412).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python-Pillow fixes the following issues - CVE-2026-42311: malicious PSD file processing can lead to arbitrary code execution (bsc#1270404). - CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). - CVE-2026-54060: fonts can trigger excessive memory allocation during conversion or saving (bsc#1270410). - CVE-2026-55379: bypass of decompression bomb protection allows excessive memory allocation (bsc#1270411). - CVE-2026-55380: crafted `.gd` file can trigger excessive C-heap allocation when loaded (bsc#1270412).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1270404
- https://bugzilla.suse.com/1270409
- https://bugzilla.suse.com/1270410
- https://bugzilla.suse.com/1270411
- https://bugzilla.suse.com/1270412
- https://www.suse.com/security/cve/CVE-2026-42311
- https://www.suse.com/security/cve/CVE-2026-54059
- https://www.suse.com/security/cve/CVE-2026-54060
- https://www.suse.com/security/cve/CVE-2026-55379
- https://www.suse.com/security/cve/CVE-2026-55380