CVE-2026-54058

EUVD-2026-43735
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 41.9%
Affected Products (NVD)
VendorProductVersion
pythonpillow
𝑥
< 12.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
pillow
bookworm
postponed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
12.3.0-1
fixed
sid
12.3.0-1
fixed
trixie
no-dsa
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
pillow
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
pillow-python2
focal
needs-triage
jammy
dne
noble
dne
resolute
dne
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
python311-Pillow
suse enterprise desktop 15 SP7
9.5.0-150400.5.25.1
fixed
suse enterprise sap 15 SP4
9.5.0-150400.5.25.1
fixed
suse enterprise sap 15 SP5
9.5.0-150400.5.25.1
fixed
suse enterprise sap 15 SP6
9.5.0-150400.5.25.1
fixed
suse enterprise sap 15 SP7
9.5.0-150400.5.25.1
fixed
suse enterprise server 15 SP4
9.5.0-150400.5.25.1
fixed
suse enterprise server 15 SP5
9.5.0-150400.5.25.1
fixed
suse enterprise server 15 SP6
9.5.0-150400.5.25.1
fixed
suse enterprise server 15 SP7
9.5.0-150400.5.25.1
fixed
python311-Pillow-tk
suse enterprise desktop 15 SP7
9.5.0-150400.5.25.1
fixed
suse enterprise sap 15 SP4
9.5.0-150400.5.25.1
fixed
suse enterprise sap 15 SP5
9.5.0-150400.5.25.1
fixed
suse enterprise sap 15 SP6
9.5.0-150400.5.25.1
fixed
suse enterprise sap 15 SP7
9.5.0-150400.5.25.1
fixed
suse enterprise server 15 SP4
9.5.0-150400.5.25.1
fixed
suse enterprise server 15 SP5
9.5.0-150400.5.25.1
fixed
suse enterprise server 15 SP6
9.5.0-150400.5.25.1
fixed
suse enterprise server 15 SP7
9.5.0-150400.5.25.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
python3-pillow
RHEL 8
0:5.1.1-23.el8_10
fixed
python3-pillow-devel
RHEL 8
0:5.1.1-23.el8_10
fixed
python3-pillow-doc
RHEL 8
0:5.1.1-23.el8_10
fixed
python3-pillow-tk
RHEL 8
0:5.1.1-23.el8_10
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
python-pillow
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.20
fixed
python-pillow-debuginfo
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.20
fixed
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.10
fixed
python-pillow-debugsource
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.10
fixed
python-pillow-devel
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.20
fixed
python-pillow-doc
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.20
fixed
python-pillow-sane
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.20
fixed
python-pillow-tk
Amazon Linux 2
0:2.0.0-23.gitd1c6db8.amzn2.0.20
fixed
python3-pillow
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.10
fixed
python3-pillow-debuginfo
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.10
fixed
python3-pillow-devel
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.10
fixed
python3-pillow-tk
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.10
fixed
python3-pillow-tk-debuginfo
Amazon Linux 2023
0:9.4.0-2.amzn2023.0.10
fixed