Security update for python-Pillow
This update for python-Pillow fixes the following issues - CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). - CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). - CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). - CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). - CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). - CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). - CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python-Pillow fixes the following issues - CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). - CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). - CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). - CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). - CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). - CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). - CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1271418
- https://bugzilla.suse.com/1271419
- https://bugzilla.suse.com/1271420
- https://bugzilla.suse.com/1271421
- https://bugzilla.suse.com/1271422
- https://bugzilla.suse.com/1271424
- https://bugzilla.suse.com/1271425
- https://www.suse.com/security/cve/CVE-2026-54058
- https://www.suse.com/security/cve/CVE-2026-59197
- https://www.suse.com/security/cve/CVE-2026-59198
- https://www.suse.com/security/cve/CVE-2026-59199
- https://www.suse.com/security/cve/CVE-2026-59200
- https://www.suse.com/security/cve/CVE-2026-59204
- https://www.suse.com/security/cve/CVE-2026-59205
- https://www.suse.com/support/update/announcement/2026/suse-su-20263084-1/