Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Fedora 43 python-pillow Denial of Service CVE-2026-40192 Advisory Info

fedora
Calendar Grey April 22, 2026
Dist Fedora Esm H88
Critical update for Python Pillow in Fedora 43 addressing Denial of Service vulnerability CVE-2026-40192.
Fix CVE-2026-40192.

Summary

Python image processing library, fork of the Python Imaging Library (PIL)

This library provides extensive file format support, an efficient

internal representation, and powerful image processing capabilities.

There are four subpackages: tk (tk interface), qt (PIL image wrapper for Qt),

devel (development) and doc (documentation).

Update Information:

Fix CVE-2026-40192.

Change Log

* Sat Apr 18 2026 Sandro Mani - 11.3.0-8 - Backport fix for CVE-2026-40192

References


[ 1 ] Bug #2459007 - CVE-2026-40192 python-pillow: Pillow: Denial of Service via decompression bomb in FITS image processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459007

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5ab72c7957' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: python-pillow
Product: Fedora 43
Version: 11.3.0
Release: 8.fc43
Summary: Python image processing library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here