ALAS2023-2026-1712


Amazon Linux 2023 Security Advisory: ALAS2023-2026-1712
Advisory Released Date: 2026-05-26
Advisory Updated Date: 2026-05-26
Severity: Important

Issue Overview:

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0. (CVE-2026-42308)

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the application unresponsive. This issue has been patched in version 12.2.0. (CVE-2026-42310)

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0. (CVE-2026-42311)


Affected Packages:

python-pillow


Issue Correction:
Run dnf update python-pillow --releasever 2023.11.20260526 or dnf update --advisory ALAS2023-2026-1712 --releasever 2023.11.20260526 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    python3-pillow-debuginfo-9.4.0-2.amzn2023.0.8.aarch64
    python3-pillow-tk-debuginfo-9.4.0-2.amzn2023.0.8.aarch64
    python-pillow-debuginfo-9.4.0-2.amzn2023.0.8.aarch64
    python3-pillow-devel-9.4.0-2.amzn2023.0.8.aarch64
    python3-pillow-tk-9.4.0-2.amzn2023.0.8.aarch64
    python-pillow-debugsource-9.4.0-2.amzn2023.0.8.aarch64
    python3-pillow-9.4.0-2.amzn2023.0.8.aarch64

src:
    python-pillow-9.4.0-2.amzn2023.0.8.src

x86_64:
    python-pillow-debuginfo-9.4.0-2.amzn2023.0.8.x86_64
    python-pillow-debugsource-9.4.0-2.amzn2023.0.8.x86_64
    python3-pillow-debuginfo-9.4.0-2.amzn2023.0.8.x86_64
    python3-pillow-tk-debuginfo-9.4.0-2.amzn2023.0.8.x86_64
    python3-pillow-tk-9.4.0-2.amzn2023.0.8.x86_64
    python3-pillow-devel-9.4.0-2.amzn2023.0.8.x86_64
    python3-pillow-9.4.0-2.amzn2023.0.8.x86_64