testing

python-pillow-11.3.0-9.fc43

FEDORA-2026-d86f55c21a created by smani 4 days ago for Fedora 43

Fix CVE-2026-55380, CVE-2026-54060, CVE-2026-54059, CVE-2026-55379, CVE-2026-55798

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-d86f55c21a

This update has been submitted for testing by smani.

4 days ago

This update's test gating status has been changed to 'waiting'.

4 days ago

This update's test gating status has been changed to 'passed'.

4 days ago

This update has been pushed to testing.

3 days ago
User Icon filiperosset commented & provided feedback a day ago
karma

no regressions noted here

User Icon derekenz commented & provided feedback 23 hours ago
karma

Works

This update can be pushed to stable now if the maintainer wishes

23 hours ago

Please log in to add feedback.

Metadata
Type
security
Severity
high
Karma
2
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
14 days
Thresholds
Minimum Karma
+2
Minimum Testing
14 days
Dates
submitted
4 days ago
in testing
3 days ago
approved
23 hours ago
BZ#2497649 CVE-2026-55379 python-pillow: Pillow: Denial of Service via crafted BDF font file [fedora-all]
0
0
BZ#2497660 CVE-2026-55380 python-pillow: Pillow: Denial of Service via crafted GD 2.x image file [fedora-all]
0
0
BZ#2497665 CVE-2026-54060 python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files [fedora-all]
0
0
BZ#2497682 CVE-2026-54059 python-pillow: Pillow: Denial of Service via crafted PCF font data [fedora-all]
0
0
BZ#2497699 CVE-2026-55798 python-pillow: Pillow: Arbitrary command injection via shell metacharacters in file paths [fedora-all]
0
0

Automated Test Results