Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 26.04 LTS 8399-1 Pillow Denial of Service Risk CVE-2026-42308

Ubuntu Large Esm H500
Several security issues were fixed in Pillow.
==========================================================================
Ubuntu Security Notice USN-8399-1
June 08, 2026

pillow vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in Pillow.

Software Description:
- pillow: Python Imaging Library

Details:

It was discovered that Pillow incorrectly handled large glyph advance
values in fonts. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. (CVE-2026-42308)

It was discovered that Pillow incorrectly handled nested coordinate lists
in certain APIs. An attacker could possibly use this issue to cause Pillow
to crash, resulting in a denial of service. This issue only affected Ubuntu
25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309)

It was discovered that Pillow incorrectly handled certain malformed PDF
files. An attacker could possibly use this issue to cause Pillow to use
excessive resources, leading to a denial of service. (CVE-2026-42310)

It was discovered that Pillow incorrectly handled certain malformed PSD
files. An attacker could possibly use this issue to cause Pillow to crash,
resulting in a denial of service, or to execute arbitrary code. This issue
only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42311)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  python3-pil                     12.1.1-2ubuntu1.2

Ubuntu 25.10
  python3-pil                     11.3.0-1ubuntu1.3

Ubuntu 24.04 LTS
  python3-pil                     10.2.0-1ubuntu1.2

Ubuntu 22.04 LTS
  python3-pil                     9.0.1-1ubuntu0.4

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8399-1
  CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311

Package Information:
  https://launchpad.net/ubuntu/+source/pillow/12.1.1-2ubuntu1.2
  https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.3
  https://launchpad.net/ubuntu/+source/pillow/10.2.0-1ubuntu1.2
  https://launchpad.net/ubuntu/+source/pillow/9.0.1-1ubuntu0.4

Ubuntu 26.04 LTS 8399-1 Pillow Denial of Service Risk CVE-2026-42308

ubuntu
Calendar Grey June 8, 2026
Dist Ubuntu Esm H88
Several security issues fixed in Pillow for various Ubuntu releases prevent potential crashes and resource misuse.
Several security issues were fixed in Pillow.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Pillow. Software Description: - pillow: Python Imaging Library Details: It was discovered that Pillow incorrectly handled large glyph advance values in fonts. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. (CVE-2026-42308) It was discovered that Pillow incorrectly handled nested coordinate lists in certain APIs. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309) It was discovered that Pillow incorrectly handled certain malformed PDF files. An attacker could possibly use this issue to cause Pillow to use excessive resources, leading to a denial of service. (CVE-2026-42310) It was discovered that Pillow incor...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pil 12.1.1-2ubuntu1.2 Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.3 Ubuntu 24.04 LTS python3-pil 10.2.0-1ubuntu1.2 Ubuntu 22.04 LTS python3-pil 9.0.1-1ubuntu0.4 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8399-1

CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311

Severity
important
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8399-1

Package Information

https://launchpad.net/ubuntu/+source/pillow/12.1.1-2ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.3 https://launchpad.net/ubuntu/+source/pillow/10.2.0-1ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/9.0.1-1ubuntu0.4

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here