Security update for python-Pillow
This update for python-Pillow fixes the following issues: - CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). - CVE-2026-54059: bomb protection bypass via PCF font loading due to `Image.frombytes()` being called without `_decompression_bomb_check()` (bsc#1270409). - CVE-2026-54060: excessive allocation due to `FontFile.compile()`: `Image.new()` being called without `_decompression_bomb_check()` (bsc#1270410). - CVE-2026-55379: bomb protection bypass via font loading due to `Image.new()` being called without `_decompression_bomb_check()` (bsc#1270411). - CVE-2026-55380: unchecked 4.3 GB C-heap allocation due to image dimensions being accepted without `_decompression_bomb_check()` in `GdImageFile._open()` (bsc#1270412). - CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). - CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). - CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). - CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). - CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). - CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch (bsc#1271425).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for python-Pillow fixes the following issues: - CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). - CVE-2026-54059: bomb protection bypass via PCF font loading due to `Image.frombytes()` being called without `_decompression_bomb_check()` (bsc#1270409). - CVE-2026-54060: excessive allocation due to `FontFile.compile()`: `Image.new()` being called without `_decompression_bomb_check()` (bsc#1270410). - CVE-2026-55379: bomb protection bypass via font loading due to `Image.new()` being called without `_decompression_bomb_check()` (bsc#1270411). - CVE-2026-55380: unchecked 4.3 GB C-heap allocation due to image dimensions being accepted without `_decompression_bomb_check()` in `GdImageFile._open()` (bsc#1270412). - CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). - CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). - CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). - CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). - CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). - CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch (bsc#1271425).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1270409
- https://bugzilla.suse.com/1270410
- https://bugzilla.suse.com/1270411
- https://bugzilla.suse.com/1270412
- https://bugzilla.suse.com/1271418
- https://bugzilla.suse.com/1271419
- https://bugzilla.suse.com/1271420
- https://bugzilla.suse.com/1271421
- https://bugzilla.suse.com/1271422
- https://bugzilla.suse.com/1271424
- https://bugzilla.suse.com/1271425
- https://www.suse.com/security/cve/CVE-2026-54058
- https://www.suse.com/security/cve/CVE-2026-54059
- https://www.suse.com/security/cve/CVE-2026-54060
- https://www.suse.com/security/cve/CVE-2026-55379
- https://www.suse.com/security/cve/CVE-2026-55380
- https://www.suse.com/security/cve/CVE-2026-59197
- https://www.suse.com/security/cve/CVE-2026-59198
- https://www.suse.com/security/cve/CVE-2026-59199
- https://www.suse.com/security/cve/CVE-2026-59200
- https://www.suse.com/security/cve/CVE-2026-59204
- https://www.suse.com/security/cve/CVE-2026-59205
- https://www.suse.com/support/update/announcement/2026/suse-su-20263268-1/