PT-2026-55964 · Pypi+2 · Pillow+2
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Pillow versions prior to 12.3.0
Description
The
bdf char() function in PIL/BdfFontFile.py reads the BBX width and height fields from a BDF font file and passes these attacker-controlled dimensions to Image.new() without invoking Image. decompression bomb check(). This bypasses the documented decompression bomb protection, which is a security mechanism designed to prevent the processing of maliciously crafted files that expand to an enormous size in memory, leading to excessive memory allocation.Recommendations
Update to version 12.3.0.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pillow
Red Os
Rocky Linux