Security update for python-Pillow
| Announcement ID: | SUSE-SU-2026:3268-1 |
|---|---|
| Release Date: | 2026-07-27T10:59:26Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves 11 vulnerabilities can now be installed.
Description:
This update for python-Pillow fixes the following issues:
- CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on
mmappath (bsc#1271419). - CVE-2026-54059: bomb protection bypass via PCF font loading due to
Image.frombytes()being called without_decompression_bomb_check()(bsc#1270409). - CVE-2026-54060: excessive allocation due to
FontFile.compile():Image.new()being called without_decompression_bomb_check()(bsc#1270410). - CVE-2026-55379: bomb protection bypass via font loading due to
Image.new()being called without_decompression_bomb_check()(bsc#1270411). - CVE-2026-55380: unchecked 4.3 GB C-heap allocation due to image dimensions being accepted without
_decompression_bomb_check()inGdImageFile._open()(bsc#1270412). - CVE-2026-59197: heap out-of-bounds write in
ImageFilter.RankFiltervia integer overflow inImagingExpand(bsc#1271418). - CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420).
- CVE-2026-59199: heap out-of-bounds write in
Image.paste()andImage.crop()via signed coordinate overflow (bsc#1271421). - CVE-2026-59200: decompression bomb DoS via
PdfParser.PdfStream.decode()(bsc#1271422). - CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424).
- CVE-2026-59205: controlled heap out-of-bounds write in
ImageCmsTransform.apply()via output mode mismatch (bsc#1271425).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3268=1 -
Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3268=1 -
SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3268=1 -
SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3268=1 -
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3268=1 -
SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3268=1 -
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3268=1 -
SUSE Linux Enterprise Server 15 SP5 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3268=1 -
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3268=1 -
SUSE Linux Enterprise Server for SAP Applications 15 SP5
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3268=1 -
SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3268=1 -
openSUSE Leap 15.4
zypper in -t patch SUSE-2026-3268=1
Package List:
-
openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64)
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64)
- python311-Pillow-9.5.0-150400.5.25.1
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64)
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
- python311-Pillow-9.5.0-150400.5.25.1
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64)
- python311-Pillow-9.5.0-150400.5.25.1
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64)
- python311-Pillow-9.5.0-150400.5.25.1
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)
- python311-Pillow-9.5.0-150400.5.25.1
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)
- python311-Pillow-9.5.0-150400.5.25.1
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64)
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)
- python311-Pillow-9.5.0-150400.5.25.1
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
-
SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
- python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-9.5.0-150400.5.25.1
- python-Pillow-debuginfo-9.5.0-150400.5.25.1
- python311-Pillow-debuginfo-9.5.0-150400.5.25.1
- python-Pillow-debugsource-9.5.0-150400.5.25.1
- python311-Pillow-tk-9.5.0-150400.5.25.1
References:
- https://www.suse.com/security/cve/CVE-2026-54058.html
- https://www.suse.com/security/cve/CVE-2026-54059.html
- https://www.suse.com/security/cve/CVE-2026-54060.html
- https://www.suse.com/security/cve/CVE-2026-55379.html
- https://www.suse.com/security/cve/CVE-2026-55380.html
- https://www.suse.com/security/cve/CVE-2026-59197.html
- https://www.suse.com/security/cve/CVE-2026-59198.html
- https://www.suse.com/security/cve/CVE-2026-59199.html
- https://www.suse.com/security/cve/CVE-2026-59200.html
- https://www.suse.com/security/cve/CVE-2026-59204.html
- https://www.suse.com/security/cve/CVE-2026-59205.html
- https://bugzilla.suse.com/show_bug.cgi?id=1270409
- https://bugzilla.suse.com/show_bug.cgi?id=1270410
- https://bugzilla.suse.com/show_bug.cgi?id=1270411
- https://bugzilla.suse.com/show_bug.cgi?id=1270412
- https://bugzilla.suse.com/show_bug.cgi?id=1271418
- https://bugzilla.suse.com/show_bug.cgi?id=1271419
- https://bugzilla.suse.com/show_bug.cgi?id=1271420
- https://bugzilla.suse.com/show_bug.cgi?id=1271421
- https://bugzilla.suse.com/show_bug.cgi?id=1271422
- https://bugzilla.suse.com/show_bug.cgi?id=1271424
- https://bugzilla.suse.com/show_bug.cgi?id=1271425