Infinite loop in Pillow - CVE-2026-42310
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an infinite loop in PdfParser when parsing a malicious PDF trailer with cyclic Prev pointers. A remote attacker can supply a specially crafted PDF file to cause a denial of service.
The issue can cause the process to hang indefinitely, consume 100% CPU, and make the application unresponsive.
Affected software
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
Anolis OS
PowerVC
python3-Pillow-tk-debuginfo
python3-Pillow-debuginfo
python-Pillow-debugsource
python3-Pillow
python-Pillow-debuginfo
python3-Pillow-tk
python3-pillow-qt
python3-pillow-help
python3-pillow-tk
python3-pillow-devel
python3-pillow
python-pillow-debugsource
python-pillow-debuginfo
python-pillow
python3-pillow-doc
How to mitigate CVE-2026-42310
python3-Pillow-tk-debuginfo - update to 7.2.0-150300.3.21.1
python3-Pillow-debuginfo - update to 7.2.0-150300.3.21.1
python-Pillow-debugsource - update to 7.2.0-150300.3.21.1
python3-Pillow - update to 7.2.0-150300.3.21.1
python-Pillow-debuginfo - update to 7.2.0-150300.3.21.1
python3-Pillow-tk - update to 7.2.0-150300.3.21.1
python3-pillow-qt - addressed in versions 9.0.1-8, 10.3.0-5
python3-pillow-help - addressed in versions 9.0.1-8, 10.3.0-5
python3-pillow-tk - addressed in versions 9.0.1-8, 10.3.0-5
python3-pillow-devel - addressed in versions 9.0.1-8, 10.3.0-5
python3-pillow - addressed in versions 9.0.1-8, 10.3.0-5
python-pillow-debugsource - addressed in versions 9.0.1-8, 10.3.0-5
python-pillow-debuginfo - addressed in versions 9.0.1-8, 10.3.0-5
python-pillow - addressed in versions 9.0.1-8, 10.3.0-5
python3-pillow - update to 12.2.0-1
python3-pillow-devel - update to 12.2.0-1
python3-pillow-qt - update to 12.2.0-1
python3-pillow-tk - update to 12.2.0-1
python3-pillow-doc - update to 12.2.0-1
External References
Related Security Bulletins
- Multiple vulnerabilities in Pillow
- openEuler 24.03 LTS update for python-pillow
- openEuler 22.03 LTS SP4 update for python-pillow
- openEuler 20.03 LTS SP4 update for python-pillow
- openEuler 24.03 LTS SP3 update for python-pillow
- SUSE update for python-Pillow
- Anolis OS update for python-pillow
- Multiple vulnerabilities in IBM PowerVC