path_getbbox in path.c in Pillow before 9.0.0 improperly initializes ImagePath.Path. References: https://github.com/python-pillow/Pillow/blob/c5d9223a8b5e9295d15b5a9b1ef1dae44c8499f3/src/path.c#L331 https://pillow.readthedocs.io/en/stable/releasenotes/9.0.0.html#fixed-imagepath-path-array-handling
Created mingw-python-pillow tracking bugs for this issue: Affects: fedora-all [bug 2042512] Created python-pillow tracking bugs for this issue: Affects: fedora-all [bug 2042513] Created python3-pillow tracking bugs for this issue: Affects: epel-7 [bug 2042514]
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-22815