Alerts This Week
Warning Icon 1 1,111
Alerts This Week
Warning Icon 1 1,111

Ubuntu 25.10 Pillow Important Denial of Service USN-8047-1 CVE-2026-25990

ubuntu
Calendar Grey February 17, 2026
Dist Ubuntu Esm H88
Pillow on Ubuntu could crash or run code due to malformed files, leading to significant threats. Update recommended.
Pillow could be made to crash or run programs if it opened a specially crafted file.

Summary

Pillow could be made to crash or run programs if it opened a specially

crafted file.

Software Description:

- pillow: Python Imaging Library

Details:

Yarden Porat discovered that Pillow incorrectly handled certain malformed

PSD images. An attacker could use this issue to cause Pillow to crash,

resulting in a denial of service, or possibly execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 25.10
  python3-pil                     11.3.0-1ubuntu1.1

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8047-1

CVE-2026-25990

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8047-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here