python-pillow-5.1.1-23.el8_10
エラータID: AXSA:2026-1435:02
Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems.
Security Fix(es):
* Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197)
* Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-54058
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.
CVE-2026-59197
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.
Update packages.
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.
N/A
SRPMS
- python-pillow-5.1.1-23.el8_10.src.rpm
MD5: 3fb31b2af676aae69c31ad734edb3c9f
SHA-256: c4841ae7269403fbe213a1ee4f747e72e0c79f9b7bd5cb2c734f406597d5fafd
Size: 13.53 MB
Asianux Server 8 for x86_64
- python3-pillow-5.1.1-23.el8_10.i686.rpm
MD5: 541a1fa4e6939a57e76b02db16fe1a66
SHA-256: 602900dfbf81c5cdd858913cc4fd56084f65fe13da975169999fe8f484cd7180
Size: 640.99 kB - python3-pillow-5.1.1-23.el8_10.x86_64.rpm
MD5: 9f1e808940d48a4ee69af7e4a694cf02
SHA-256: ae0d5ceaa312fedcc82e6ce95963bafc5acfbfe84aed856b53d93b045b5dd2d9
Size: 632.34 kB - python3-pillow-devel-5.1.1-23.el8_10.i686.rpm
MD5: d1e02fa63e9fa7406389099c8a05faa0
SHA-256: 28efee1a1f7285acb9b49c1bf6d8cad4944c15a093b37eadcb8186049636d7a6
Size: 33.88 kB - python3-pillow-devel-5.1.1-23.el8_10.x86_64.rpm
MD5: cf61efd5934a3048b7d241ad0a6f93c5
SHA-256: 2beef4211cf921d82611030c592472bcd6dbf4f74b284813a1a497b80b0200e2
Size: 33.85 kB - python3-pillow-doc-5.1.1-23.el8_10.noarch.rpm
MD5: cf99825c91c13be5b5e49bf4f575d73c
SHA-256: af32fca5e3348dc9b23a1da7352c255cc4a408673c33f73a4b503492ff7cdb58
Size: 1.99 MB - python3-pillow-tk-5.1.1-23.el8_10.x86_64.rpm
MD5: 2ffc5708f7cf84f3ef7be6494706926f
SHA-256: 85f1edc2930c3b0210deefbde0c068d663bfad61a458db6b8d237a32c5772bda
Size: 37.01 kB