Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
This update for python-Pillow fixes the following issues:
* CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on
`mmap` path (bsc#1271419).
* CVE-2026-54059: bomb protection bypass via PCF font loading due to
`Image.frombytes()` being called without `_decompression_bomb_check()`
(bsc#1270409).
* CVE-2026-54060: excessive allocation due to `FontFile.compile()`:
`Image.new()` being called without `_decompression_bomb_check()`
(bsc#1270410).
* CVE-2026-55379: bomb protection bypass via font loading due to `Image.new()`
being called without `_decompression_bomb_check()` (bsc#1270411).
* CVE-2026-55380: unchecked 4.3 GB C-heap allocation due to image dimensions
being accepted without `_decompression_bomb_check()` in
`GdImageFile._open()` (bsc#1270412).
* CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via
integer overflow in `ImagingExpand` (bsc#1271418).
* CVE-2026-59198: out-of-bounds heap data...
Read the Full Advisory## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3268=1
* Python 3 Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3268=1
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3268=1
* SUSE Linux Enterprise Server 15 SP4 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3268=1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5
zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3268=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP4
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3268=1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4
zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3268=1
*...
Read the Full Advisory* openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64
x86_64)
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-tk-9.5.0-150400.5.25.1
* SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64
x86_64)
* python311-Pillow-9.5.0-150400.5.25.1
* python311-Pillow-tk-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debuginfo-9.5.0-150400.5.25.1
* python-Pillow-debugsource-9.5.0-150400.5.25.1
* python311-Pillow-debuginfo-9.5.0-150400.5.25.1
*...
Read the Full Advisory* bsc#1270409
* bsc#1270410
* bsc#1270411
* bsc#1270412
* bsc#1271418
* bsc#1271419
* bsc#1271420
* bsc#1271421
* bsc#1271422
* bsc#1271424
* bsc#1271425
## References:
* https://www.suse.com/security/cve/CVE-2026-54058.html
* https://www.suse.com/security/cve/CVE-2026-54059.html
* https://www.suse.com/security/cve/CVE-2026-54060.html
* https://www.suse.com/security/cve/CVE-2026-55379.html
* https://www.suse.com/security/cve/CVE-2026-55380.html
* https://www.suse.com/security/cve/CVE-2026-59197.html
* https://www.suse.com/security/cve/CVE-2026-59198.html
* https://www.suse.com/security/cve/CVE-2026-59199.html
* https://www.suse.com/security/cve/CVE-2026-59200.html
* https://www.suse.com/security/cve/CVE-2026-59204.html
* https://www.suse.com/security/cve/CVE-2026-59205.html
* https://bugzilla.suse.com/show_bug.cgi?id=1270409
* https://bugzilla.suse.com/show_bug.cgi?id=1270410
* https://bugzilla.suse.com/show_bug.cgi?id=1270411
* https://bugzilla.suse.com/show_bug.cgi?id=1270412
*...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.