Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Multiple security vulnerabilities have been discovered in Pillow, a Python imaging library, which could result in denial of service or the execution of arbitrary code if malformed files are processed. For the stable distribution (trixie), these problems have been fixed in version 11.1.0-5+deb13u3.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6357-1
Several security issues were fixed in Pillow.. ========================================================================== Ubuntu Security Notice USN-8399-1 June 08, 2026 pillow vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Pillow. Software Description: - pillow: Python Imaging Library Details: It was discovered that Pillow incorrectly handled large glyph advance values in fonts. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. (CVE-2026-42308) It was discovered that Pillow incorrectly handled nested coordinate lists in certain APIs. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309) It was discovered that Pillow incorrectly handled certain malformed PDF files. An attacker could possibly use this issue to cause Pillow to use excessive resources, leading to a denial of service. (CVE-2026-42310) It was discovered that Pillow incorrectly handled certain malformed PSD files. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service, or to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42311) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pil 12.1.1-2ubuntu1.2 Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.3 Ubuntu 24.04 LTS python3-pil 10.2.0-1ubuntu1.2 Ubuntu 22.04 LTS python3-pil 9.0.1-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8399-1 CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311 Package Information: https://launchpad.net/ubuntu/+source/pillow/12.1.1-2ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.3 https://launchpad.net/ubuntu/+source/pillow/10.2.0-1ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/9.0.1-1ubuntu0.4 . Several security issues fixed in Pillow for various Ubuntu releases prevent potential crashes and resource misuse.. Ubuntu security patches, Pillow library issues, Python Imaging denial of service, Ubuntu vulnerabilities. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Pillow.. ========================================================================== Ubuntu Security Notice USN-8399-1 June 08, 2026 pillow vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Pillow. Software Description: - pillow: Python Imaging Library Details: It was discovered that Pillow incorrectly handled large glyph advance values in fonts. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. (CVE-2026-42308) It was discovered that Pillow incorrectly handled nested coordinate lists in certain APIs. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309) It was discovered that Pillow incorrectly handled certain malformed PDF files. An attacker could possibly use this issue to cause Pillow to use excessive resources, leading to a denial of service. (CVE-2026-42310) It was discovered that Pillow incorrectly handled certain malformed PSD files. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service, or to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42311) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pil 12.1.1-2ubuntu1.2 Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.3 Ubuntu 24.04 LTS python3-pil 10.2.0-1ubuntu1.2 Ubuntu 22.04 LTS python3-pil 9.0.1-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8399-1 CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311 Package Information: https://launchpad.net/ubuntu/+source/pillow/12.1.1-2ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.3 https://launchpad.net/ubuntu/+source/pillow/10.2.0-1ubuntu1.2 https://launchpad.net/ubuntu/+source/pillow/9.0.1-1ubuntu0.4 . Explore critical updates to Pillow in Ubuntu, fixing multiple denial-of-service risks and enhancing system security.. Pillow update, Ubuntu security, denial of service, Pillow vulnerabilities, Ubuntu advisory. . Severity: Critical. LinuxSecurity.com Team
Pillow could be made to crash if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8211-1 April 27, 2026 pillow vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: Pillow could be made to crash if it opened a specially crafted file. Software Description: - pillow: Python Imaging Library Details: It was discovered that Pillow incorrectly handled certain FITS images. An attacker could possibly use this issue to cause Pillow to consume resources, leading to a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.2 python3-pil.imagetk 11.3.0-1ubuntu1.2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8211-1 CVE-2026-40192 Package Information: https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.2 . Pillow crash risk on Ubuntu 25.10 addresses crucial update for denial of service vulnerability.. Ubuntu security,Pillow update,denial of service,security patch,resource crash. . Severity: Important. LinuxSecurity.com Team
It was discovered that missing input sanitising in the FITS support of Pillow, a Python imaging library, could result in denial of service. The oldstable distribution (bookworm) is not affected. For the stable distribution (trixie), this problem has been fixed in version 11.1.0-5+deb13u2.. - ------------------------------------------------------------------------- Debian Security Advisory DSA-6219-1
Pillow could be made to crash or run programs if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-8047-1 February 17, 2026 pillow vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 Summary: Pillow could be made to crash or run programs if it opened a specially crafted file. Software Description: - pillow: Python Imaging Library Details: Yarden Porat discovered that Pillow incorrectly handled certain malformed PSD images. An attacker could use this issue to cause Pillow to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8047-1 CVE-2026-25990 Package Information: https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubuntu1.1 . Pillow on Ubuntu could crash or run code due to malformed files, leading to significant threats. Update recommended.. Pillow update Ubuntu crash security. . Severity: Important. LinuxSecurity.com Team
Multiple vulnerabilities have been found in Pillow, an image processing library for Python. CVE-2021-23437 The getrgb function is susceptible to a ReDoS. CVE-2022-24303. ------------------------------------------------------------------------- Debian LTS Advisory DLA-4462-1
A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202411-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: Pillow: Arbitrary code execution Date: November 17, 2024 Bugs: #928391 ID: 202411-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== A vulnerability has been discovered in Pillow, which may lead to arbitrary code execution. Background ========== The friendly PIL fork. Affected packages ================= Package Vulnerable Unaffected ----------------- ------------ ------------ dev-python/pillow < 10.3.0 > = 10.3.0 Description =========== A vulnerability has been discovered in Pillow. Please review the CVE identifier referenced below for details. Impact ====== Please review the referenced CVE identifier for details. Workaround ========== There is no known workaround at this time. Resolution ========== All Pillow users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-python/pillow-10.3.0" References ========== [ 1 ] CVE-2024-28219 https://nvd.nist.gov/vuln/detail/CVE-2024-28219 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202411-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.