Infinite loop in Pillow - CVE-2026-42310
Published: April 23, 2026
Pillow
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
Anolis OS
python3-Pillow-tk-debuginfo
python3-Pillow-debuginfo
python-Pillow-debugsource
python3-Pillow
python-Pillow-debuginfo
python3-Pillow-tk
python3-pillow-qt
python3-pillow-help
python3-pillow-tk
python3-pillow-devel
python3-pillow
python-pillow-debugsource
python-pillow-debuginfo
python-pillow
python3-pillow-doc
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an infinite loop in PdfParser when parsing a malicious PDF trailer with cyclic Prev pointers. A remote attacker can supply a specially crafted PDF file to cause a denial of service.
The issue can cause the process to hang indefinitely, consume 100% CPU, and make the application unresponsive.