CVE-2026-42308

NameCVE-2026-42308
DescriptionPillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
pillow (PTS)bullseye8.1.2+dfsg-0.3+deb11u2vulnerable
bullseye (security)8.1.2+dfsg-0.3+deb11u3vulnerable
bookworm, bookworm (security)9.4.0-1.1+deb12u1vulnerable
trixie (security), trixie11.1.0-5+deb13u2vulnerable
forky, sid12.2.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
pillowsource(unstable)12.2.0-1

Notes

[bullseye] - pillow <postponed> (Minor issue, UBSAN)
https://github.com/python-pillow/Pillow/security/advisories/GHSA-wjx4-4jcj-g98j
research fixing commit(s), maybe https://github.com/python-pillow/Pillow/pull/9518/changes

Search for package or bug name: Reporting problems