Bug 2500043 (CVE-2026-59197) - CVE-2026-59197 Pillow: Pillow: Native heap out-of-bounds write
Summary: CVE-2026-59197 Pillow: Pillow: Native heap out-of-bounds write
Keywords:
Status: NEW
Alias: CVE-2026-59197
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2501493 2501494
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-14 17:01 UTC by OSIDB Bzimport
Modified: 2026-08-15 08:27 UTC (History)
55 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2026:48021 0 None None None 2026-07-29 21:03:17 UTC
Red Hat Product Errata RHSA-2026:50223 0 None None None 2026-08-04 15:59:37 UTC
Red Hat Product Errata RHSA-2026:50319 0 None None None 2026-08-04 17:56:59 UTC
Red Hat Product Errata RHSA-2026:50336 0 None None None 2026-08-04 18:44:30 UTC
Red Hat Product Errata RHSA-2026:52551 0 None None None 2026-08-10 03:58:11 UTC
Red Hat Product Errata RHSA-2026:54417 0 None None None 2026-08-12 18:17:18 UTC
Red Hat Product Errata RHSA-2026:54528 0 None None None 2026-08-13 11:08:39 UTC

Description OSIDB Bzimport 2026-07-14 17:01:52 UTC
Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public rank-filter API can trigger a native heap out-of-bounds write when given a very large odd filter size because ImageFilter.RankFilter.filter() calls image.expand(size // 2, size // 2) before rank-filter size validation and ImagingExpand() computes output dimensions with unchecked signed int arithmetic. This issue is fixed in version 12.3.0.

Comment 5 errata-xmlrpc 2026-07-29 21:03:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:48021 https://access.redhat.com/errata/RHSA-2026:48021

Comment 6 errata-xmlrpc 2026-08-04 15:59:33 UTC
This issue has been addressed in the following products:

  Red Hat Satellite 6.16 for RHEL 8
  Red Hat Satellite 6.16 for RHEL 9

Via RHSA-2026:50223 https://access.redhat.com/errata/RHSA-2026:50223

Comment 7 errata-xmlrpc 2026-08-04 17:56:53 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.5 for RHEL 9
  Red Hat Ansible Automation Platform 2.5 for RHEL 8

Via RHSA-2026:50319 https://access.redhat.com/errata/RHSA-2026:50319

Comment 8 errata-xmlrpc 2026-08-04 18:44:26 UTC
This issue has been addressed in the following products:

  Red Hat Ansible Automation Platform 2.6 for RHEL 9
  Red Hat Ansible Automation Platform 2.6 for RHEL 10

Via RHSA-2026:50336 https://access.redhat.com/errata/RHSA-2026:50336

Comment 9 errata-xmlrpc 2026-08-10 03:58:07 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:52551 https://access.redhat.com/errata/RHSA-2026:52551

Comment 10 errata-xmlrpc 2026-08-12 18:17:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:54417 https://access.redhat.com/errata/RHSA-2026:54417

Comment 11 errata-xmlrpc 2026-08-13 11:08:35 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:54528 https://access.redhat.com/errata/RHSA-2026:54528


Note You need to log in before you can comment on or make changes to this bug.