Name | CVE-2025-48379 |
Description | Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
pillow (PTS) | bullseye (security), bullseye | 8.1.2+dfsg-0.3+deb11u2 | fixed |
| bookworm, bookworm (security) | 9.4.0-1.1+deb12u1 | fixed |
| sid, trixie | 11.1.0-5 | fixed |
The information below is based on the following data on fixed versions.
Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
---|
pillow | source | (unstable) | (not affected) | | | |
Notes
- pillow <not-affected> (Vulnerable code not present)
https://github.com/python-pillow/Pillow/security/advisories/GHSA-xg8h-j46f-w952
https://github.com/python-pillow/Pillow/pull/9041
Fixed by: https://github.com/python-pillow/Pillow/commit/ef98b3510e3e4f14b547762764813d7e5ca3c5a4 (11.3.0)