Integer overflow in Pillow - CVE-2026-42308
Published: April 23, 2026
Vulnerability identifier: #VU127175
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-42308
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Affected software:
Pillow
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
Anolis OS
python3-Pillow-tk
python-Pillow-debuginfo
python3-Pillow-tk-debuginfo
python-Pillow-debugsource
python3-Pillow-debuginfo
python3-Pillow
python3-pillow-qt
python3-pillow-help
python3-pillow-tk
python3-pillow-devel
python3-pillow
python-pillow-debugsource
python-pillow-debuginfo
python-pillow
python3-pillow-doc
Pillow
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
Anolis OS
python3-Pillow-tk
python-Pillow-debuginfo
python3-Pillow-tk-debuginfo
python-Pillow-debugsource
python3-Pillow-debuginfo
python3-Pillow
python3-pillow-qt
python3-pillow-help
python3-pillow-tk
python3-pillow-devel
python3-pillow
python-pillow-debugsource
python-pillow-debuginfo
python-pillow
python3-pillow-doc
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in font processing when handling fonts with excessively large glyph advance values. A remote attacker can supply a specially crafted font to cause a denial of service.
How to mitigate CVE-2026-42308
Install security update from vendor's website.