Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-54058: Pillow may expose memory when processing crafted images

CVE-2026-54058 · published 2 months ago
Summary

Versions of the Pillow image library before 12.3.0 can read beyond the intended image data when a specially crafted McIdas AREA file is opened. This can allow other data in the program's memory to be revealed or cause a crash. Update Pillow to version 12.3.0 or later to stop the issue.

What to do
  • Update rootio-pillow to version 9.3.0+root.io.9.
  • Update jeffrey 'alex' clark pillow to version 12.3.0.
  • Update jeffrey 'alex' clark pillow to version 9.3.0+aikido.10.
  • Update jeffrey 'alex' clark pillow to version 11.1.0+aikido.9.
  • Update debian pillow to version 12.3.0-1.
  • Update jeffrey 'alex' clark pillow to version 10.3.0+aikido.13.
  • Update jeffrey 'alex' clark pillow to version 10.4.0+aikido.12.
  • Update jeffrey 'alex' clark pillow to version 11.0.0+aikido.11.
  • Update pillow to version 12.3.0.
  • Update python pillow to version 12.3.0 or later.
Affected software
Ecosystem VendorProductAffected versions
Root:PyPI – rootio-pillow < 9.3.0+root.io.9
Fix: upgrade to 9.3.0+root.io.9
Debian:11 debian pillow All versions
Debian:12 debian pillow All versions
Debian:13 debian pillow All versions
Debian:14 debian pillow < 12.3.0-1
Fix: upgrade to 12.3.0-1
– python-pillow pillow < 12.3.0
pip jeffrey 'alex' clark pillow < 12.3.0
Fix: upgrade to 12.3.0
Root:PyPI jeffrey 'alex' clark pillow < 9.3.0+aikido.10
< 11.1.0+aikido.9
< 10.3.0+aikido.13
< 10.4.0+aikido.12
< 11.0.0+aikido.11
Fix: upgrade to 9.3.0+aikido.10
– python pillow < 12.3.0
cpe:2.3:a:python:pillow:*:*:*:*:*:*:*:*
Ubuntu:Pro:14.04:LTS canonical pillow All versions
Ubuntu:Pro:16.04:LTS canonical pillow All versions
Ubuntu:Pro:18.04:LTS canonical pillow All versions
Ubuntu:Pro:20.04:LTS canonical pillow All versions
Ubuntu:Pro:20.04:LTS canonical pillow-python2 All versions
Ubuntu:22.04:LTS canonical pillow All versions
Ubuntu:24.04:LTS canonical pillow All versions
Ubuntu:26.04:LTS canonical pillow All versions
Bitnami – pillow < 12.3.0
Fix: upgrade to 12.3.0
Original advisory text
Pillow: Out-of-bounds read via attacker-controlled row stride on Pillow's mmap path (McIdas AREA files)
Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads an uncompressed McIdas AREA image from a filename through the mmap raw codec path, attacker-controlled header words can set a row stride smaller than the natural row width, causing pixel access such as Image.tobytes(), getpixel, convert, or save to read beyond the mapped region and disclose adjacent process memory or fault. This issue is fixed in version 12.3.0.
Severity
9.1 Critical
CVSS 4.0: 9.1 (OSV)
Exploitation
EPSS <1%
Type
CWE-125Out-of-bounds Read
Timeline
Published14 Jul 2026
Updated25 Sep 2026
First seen14 Jul 2026
Track software like this
Free during beta