Ubuntu alert USN-8399-1 (pillow)
| From: | noreply+usn-bot--- via ubuntu-security-announce <ubuntu-security-announce@lists.ubuntu.com> | |
| To: | ubuntu-security-announce@lists.ubuntu.com | |
| Subject: | [USN-8399-1] Pillow vulnerabilities | |
| Date: | Mon, 08 Jun 2026 14:06:24 +0000 | |
| Message-ID: | <E1wWacS-0004XI-SW@lists.ubuntu.com> | |
| Cc: | noreply+usn-bot@canonical.com |
========================================================================== Ubuntu Security Notice USN-8399-1 June 08, 2026 pillow vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in Pillow. Software Description: - pillow: Python Imaging Library Details: It was discovered that Pillow incorrectly handled large glyph advance values in fonts. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. (CVE-2026-42308) It was discovered that Pillow incorrectly handled nested coordinate lists in certain APIs. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309) It was discovered that Pillow incorrectly handled certain malformed PDF files. An attacker could possibly use this issue to cause Pillow to use excessive resources, leading to a denial of service. (CVE-2026-42310) It was discovered that Pillow incorrectly handled certain malformed PSD files. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service, or to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42311) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS python3-pil 12.1.1-2ubuntu1.2 Ubuntu 25.10 python3-pil 11.3.0-1ubuntu1.3 Ubuntu 24.04 LTS python3-pil 10.2.0-1ubuntu1.2 Ubuntu 22.04 LTS python3-pil 9.0.1-1ubuntu0.4 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8399-1 CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, CVE-2026-42311 Package Information: https://launchpad.net/ubuntu/+source/pillow/12.1.1-2ubunt... https://launchpad.net/ubuntu/+source/pillow/11.3.0-1ubunt... https://launchpad.net/ubuntu/+source/pillow/10.2.0-1ubunt... https://launchpad.net/ubuntu/+source/pillow/9.0.1-1ubuntu0.4
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmomzBcACgkQcpJm3tlz hgFxhxAAumlag+JXDjmHG6AYYt/1plW5AF2iqUBh125AVBttmUpse/PIheGzgIo0 7Lshna+yM8znKNCl5q9507bxamYr4556OE2kRNVOuhWtLxpAWmEXZKjCbO6gsQa4 0EQYqLJVqDIsAHiSND15uNNbb/MJ3UpqHfxjrfyzDWGKY9Z6IB7lC7DGb7oGlZey bqQbj568fx8Ck+dz1hucPHDULg0PbeMOVs6pW7rN/67kosrut0etPzCizbQ8xiuF PA31/0WuliiKdifAZTroY9YlYGl+QtNXFdI5a9uqzz6nPtq5ofz/QP18LNDvZ/nS uWqC7DzN13ekytZCVRE5VAkcJ2PDV7G6vLJyOa5EHtnplwG1R9aQsfQDPJHMcb8o isDGB5q6q/NFLpYjQGEAE2JHS1/lUzh1jO93bVBbYp+IXxPe/ci4b66J/cDjw4+u wB1BQPzsZUjWWKRi0u8kkDaCWGNa44R7vR9996TQRnwkXof/5gHKq8Wfc5l1FdsL dKfyw5OFzq++O6bb4ouY+M9hmYLE2VFznz7sfgSmwpO87JrcmExMVKAJhBiLcmQE H4KNNW69mLx2EUOHlyZ0o2iwnDxEazGhkptQaFcL2c13xo4eTYlqxGqOxAYLA6DT lpe4NeNGoZolQwILcozVP0lQic5KL7WhXD4VU1A3BU6KxYfLP8g= =FrjX -----END PGP SIGNATURE-----
