PT-2026-58104 · Pypi+2 · Pillow+2

CVE-2026-54058

·

Published

2026-06-26

·

Updated

2026-08-31

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Pillow versions prior to 12.3.0
Description An out-of-bounds read issue exists in the PyImaging MapBuffer() function within src/map.c when loading uncompressed McIdas AREA images from a filename using the mmap raw codec path. The software fails to verify that the row stride is at least the natural row width (xsize * pixelsize). A remote attacker can provide a specially crafted image with header words that set a stride smaller than the row width, causing pixel access operations—such as Image.tobytes(), getpixel, convert, or save—to read beyond the mapped memory region. This can lead to the disclosure of adjacent process memory or cause a denial of service via a SIGBUS fault.
Recommendations Update Pillow to version 12.3.0. As a temporary mitigation, restrict the use of the PyImaging MapBuffer() function or avoid processing uncompressed McIdas AREA images from untrusted sources.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:48021
BDU:2026-09900
BIT-PILLOW-2026-54058
CVE-2026-54058
ECHO-F65C-DF45-7F47
GHSA-62P4-GMF7-7G93
OESA-2026-3185
OESA-2026-3186
OESA-2026-3187
OESA-2026-3188
OESA-2026-3189
OPENSUSE-SU-2026:11283-1
OPENSUSE-SU-2026:21544-1
PYSEC-2026-3493
RHSA-2026:48021
RHSA-2026:52551
RHSA-2026:54417
RHSA-2026:54528
SUSE-SU-2026:23217-1
SUSE-SU-2026:23228-1
SUSE-SU-2026:3084-1
SUSE-SU-2026:3268-1

Affected Products

Pillow
Red Os
Rocky Linux