FlawAtlas
Search the atlas
OPENSUSE-SU-2026:21544-1 Not scored

Security update for python-Pillow

This update for python-Pillow fixes the following issues - CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). - CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). - CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). - CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). - CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). - CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). - CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch (bsc#1271425).

Exploit probability Not scored
Published August 10, 2026
Required by Not available
Last source change August 12, 2026

02 / AFFECTED SOFTWARE

Affected packages

openSUSE:Leap 16.0 python-Pillow

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2026:21544-1

This update for python-Pillow fixes the following issues - CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). - CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). - CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). - CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). - CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). - CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). - CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch (bsc#1271425).

View original source

05 / REFERENCES

Further evidence