UbuntuUpdates.org

Package "pillow"

Name: pillow

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Examples for the Python Imaging Library
  • Python Imaging Library (Python3)

Latest version: 11.3.0-1ubuntu1.2
Release: questing (25.10)
Level: updates
Repository: main

Links



Other versions of "pillow" in Questing

Repository Area Version
base main 11.3.0-1ubuntu1
base universe 11.3.0-1ubuntu1
security main 11.3.0-1ubuntu1.2
security universe 11.3.0-1ubuntu1.2
updates universe 11.3.0-1ubuntu1.2

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 11.3.0-1ubuntu1.2 2026-04-27 14:11:14 UTC

  pillow (11.3.0-1ubuntu1.2) questing-security; urgency=medium

  * SECURITY UPDATE: unbounded memory consumption via FITS image
    - debian/patches/CVE-2026-40192.patch: only read as much data from
      gzip-decompressed data as necessary in src/PIL/FitsImagePlugin.py.
    - CVE-2026-40192

 -- Marc Deslauriers <email address hidden> Tue, 21 Apr 2026 07:54:05 -0400

Source diff to previous version
CVE-2026-40192 Pillow is a Python imaging library. Versions 10.3.0 through 12.1.1 did not limit the amount of GZIP-compressed data read when decoding a FITS image,

Version: 11.3.0-1ubuntu1.1 2026-02-17 22:08:39 UTC

  pillow (11.3.0-1ubuntu1.1) questing-security; urgency=medium

  * SECURITY UPDATE: OOB write via PSD image
    - debian/patches/CVE-2026-25990.patch: fix OOB Write with invalid tile
      extents in Tests/test_imagefile.py, src/decode.c, src/encode.c.
    - CVE-2026-25990

 -- Marc Deslauriers <email address hidden> Fri, 13 Feb 2026 08:40:02 -0500

CVE-2026-25990 Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, n out-of-bounds write may be triggered when loading a specially crafted PSD image.



About   -   Send Feedback to @ubuntu_updates