Alerts This Week
Warning Icon 1 1,220
Alerts This Week
Warning Icon 1 1,220

Fedora 42 python-pillow Critical Out-of-bounds Fix CVE-2026-25990

fedora
Calendar Grey March 3, 2026
Dist Fedora Esm H88
A critical backport fix for CVE-2026-25990 in python-pillow available for Fedora 42, addressing out-of-bounds writes.
Backport fix for CVE-2026-25990.

Summary

Python image processing library, fork of the Python Imaging Library (PIL)

This library provides extensive file format support, an efficient

internal representation, and powerful image processing capabilities.

There are four subpackages: tk (tk interface), qt (PIL image wrapper for Qt),

devel (development) and doc (documentation).

Update Information:

Backport fix for CVE-2026-25990.

Change Log

* Sat Feb 14 2026 Sandro Mani - 11.1.0-3 - Backport fix for CVE-2026-25990

References


[ 1 ] Bug #2439192 - CVE-2026-25990 python-pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2439192 [ 2 ] Bug #2439196 - CVE-2026-25990 python-pillow: Pillow: Out-of-bounds Write via Specially Crafted PSD Image [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2439196

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-0d673fa503' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-pillow
Product: Fedora 42
Version: 11.1.0
Release: 3.fc42
Summary: Python image processing library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here