stable

python-pillow-12.3.0-1.fc44

FEDORA-2026-46c4892063 created by smani 4 days ago for Fedora 44

Fix CVE-2026-55380, CVE-2026-54060, CVE-2026-54059, CVE-2026-55379, CVE-2026-55798

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-46c4892063

This update has been submitted for testing by smani.

4 days ago

This update's test gating status has been changed to 'waiting'.

4 days ago

This update's test gating status has been changed to 'passed'.

4 days ago

This update has been pushed to testing.

3 days ago
User Icon besser82 commented & provided feedback 3 days ago
karma

Works great! LGTM! =)

karma

This update can be pushed to stable now if the maintainer wishes

3 days ago
User Icon rai510 provided feedback 2 days ago
karma

This update has been submitted for stable by bodhi.

2 days ago
User Icon rai510 provided feedback 2 days ago
karma
User Icon derekenz commented & provided feedback 2 days ago
karma

Works

User Icon filiperosset commented & provided feedback a day ago
karma

no regressions noted here

This update has been pushed to stable.

a day ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
5
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Dates
submitted
4 days ago
in testing
3 days ago
in stable
a day ago
approved
3 days ago
BZ#2497649 CVE-2026-55379 python-pillow: Pillow: Denial of Service via crafted BDF font file [fedora-all]
0
0
BZ#2497660 CVE-2026-55380 python-pillow: Pillow: Denial of Service via crafted GD 2.x image file [fedora-all]
0
0
BZ#2497665 CVE-2026-54060 python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files [fedora-all]
0
0
BZ#2497682 CVE-2026-54059 python-pillow: Pillow: Denial of Service via crafted PCF font data [fedora-all]
0
0
BZ#2497699 CVE-2026-55798 python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths [fedora-all]
0
0

Automated Test Results