Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-54058: Pillow may expose memory when processing crafted images
CVE-2026-54058 · published 2 months ago
Summary
Versions of the Pillow image library before 12.3.0 can read beyond the intended image data when a specially crafted McIdas AREA file is opened. This can allow other data in the program's memory to be revealed or cause a crash. Update Pillow to version 12.3.0 or later to stop the issue.
What to do
- Update rootio-pillow to version 9.3.0+root.io.9.
- Update jeffrey 'alex' clark pillow to version 12.3.0.
- Update jeffrey 'alex' clark pillow to version 9.3.0+aikido.10.
- Update jeffrey 'alex' clark pillow to version 11.1.0+aikido.9.
- Update debian pillow to version 12.3.0-1.
- Update jeffrey 'alex' clark pillow to version 10.3.0+aikido.13.
- Update jeffrey 'alex' clark pillow to version 10.4.0+aikido.12.
- Update jeffrey 'alex' clark pillow to version 11.0.0+aikido.11.
- Update pillow to version 12.3.0.
- Update python pillow to version 12.3.0 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Root:PyPI | – | rootio-pillow |
< 9.3.0+root.io.9 Fix: upgrade to 9.3.0+root.io.9
|
| Debian:11 | debian | pillow | All versions |
| Debian:12 | debian | pillow | All versions |
| Debian:13 | debian | pillow | All versions |
| Debian:14 | debian | pillow |
< 12.3.0-1 Fix: upgrade to 12.3.0-1
|
| – | python-pillow | pillow | < 12.3.0 |
| pip | jeffrey 'alex' clark | pillow |
< 12.3.0 Fix: upgrade to 12.3.0
|
| Root:PyPI | jeffrey 'alex' clark | pillow |
< 9.3.0+aikido.10 < 11.1.0+aikido.9 < 10.3.0+aikido.13 < 10.4.0+aikido.12 < 11.0.0+aikido.11 Fix: upgrade to 9.3.0+aikido.10
|
| – | python | pillow |
< 12.3.0 cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:* |
| Ubuntu:Pro:14.04:LTS | canonical | pillow | All versions |
| Ubuntu:Pro:16.04:LTS | canonical | pillow | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | pillow | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | pillow | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | pillow-python2 | All versions |
| Ubuntu:22.04:LTS | canonical | pillow | All versions |
| Ubuntu:24.04:LTS | canonical | pillow | All versions |
| Ubuntu:26.04:LTS | canonical | pillow | All versions |
| Bitnami | – | pillow |
< 12.3.0 Fix: upgrade to 12.3.0
|
Original advisory text
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.
References
- https://security-tracker.debian.org/tracker/CVE-2026-54058 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-54058 Vendor Advisory
- https://github.com/advisories/GHSA-62p4-gmf7-7g93
- https://github.com/python-pillow/Pillow Product
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54058... Vendor Advisory
- https://ubuntu.com/security/CVE-2026-54058 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-54058 Third Party Advisory
- https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90... Patch
- https://github.com/python-pillow/Pillow/pull/9719 Third Party Advisory
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93 Third Party Advisory
- https://github.com/python-pillow/Pillow/releases/tag/12.3.0 Third Party Advisory
Severity
9.1
Critical
CVSS 4.0: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-125Out-of-bounds Read
Timeline
Published14 Jul 2026
Updated25 Sep 2026
First seen14 Jul 2026
Sources
DEBIAN-CVE-2026-54058 · OSV
CVE-2026-54058 · NVD
CVE-2026-54058 · MITRE
GHSA-62p4-gmf7-7g93 · GHSA
GHSA-62p4-gmf7-7g93 · OSV
CVE-2026-54058 · OSV
UBUNTU-CVE-2026-54058 · OSV
BIT-pillow-2026-54058 · OSV
Track software like this
Free during beta