Updated python-pillow packages fix security vulnerabilities
Publication date: 01 Oct 2026Modification date: 30 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-55380 , CVE-2026-54060 , CVE-2026-54059 , CVE-2026-55379 , CVE-2026-59205 , CVE-2026-59199 , CVE-2026-59197 , CVE-2026-59198 , CVE-2026-54058 , CVE-2026-59204 , CVE-2026-59203
Description
Prevent decompression bomb when parsing PDF
WindowsViewer.get_command injection
EPS image infinite loop
JPEG2000 image memory usage
McIdas out-of-bounds (OOB) read
Out-of-bounds (OOB) read when saving 1 mode TGA images
Out-of-bounds (OOB) write from large RankFilter sizes
Out-of-bounds (OOB) write from Image.paste()
Out-of-bounds (OOB) write in ImageCmsTransform
Prevent FontFile decompression bomb
Prevent GD decompression bomb
References
- https://bugs.mageia.org/show_bug.cgi?id=35909
- https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst
- https://www.cve.org/CVERecord?id=CVE-2026-55380
- https://www.cve.org/CVERecord?id=CVE-2026-54060
- https://www.cve.org/CVERecord?id=CVE-2026-54059
- https://www.cve.org/CVERecord?id=CVE-2026-55379
- https://www.cve.org/CVERecord?id=CVE-2026-59205
- https://www.cve.org/CVERecord?id=CVE-2026-59199
- https://www.cve.org/CVERecord?id=CVE-2026-59197
- https://www.cve.org/CVERecord?id=CVE-2026-59198
- https://www.cve.org/CVERecord?id=CVE-2026-54058
- https://www.cve.org/CVERecord?id=CVE-2026-59204
- https://www.cve.org/CVERecord?id=CVE-2026-59203
SRPMS
10/core
- python-pillow-12.3.0-1.mga10