Multiple Pillow Vulnerabilities Affect Ubuntu Users

Multiple Pillow Vulnerabilities Affect Ubuntu Users

First seen 8 Jun 2026, 21:23 UTC UbuntuLinuxsecurity 92% similarity 57.9

Article Content

Browse articles
ThreatCluster

On June 8, 2026, Ubuntu released USN-8399-1 addressing several vulnerabilities in the Pillow library. These vulnerabilities could allow attackers to exploit large glyph advance values, nested coordinate lists, and malformed PDF and PSD files, potentially leading to denial of service attacks. The affected versions include Ubuntu 25.10 and Ubuntu 26.04 LTS. Specific CVEs include CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, and CVE-2026-42311, all published on May 9, 2026. Users are advised to update their systems to mitigate these risks. The vulnerabilities could allow excessive resource usage or crashes, impacting service availability. The issues highlight the importance of timely software updates for maintaining security.

Key Points: • Pillow vulnerabilities could lead to denial of service attacks on affected Ubuntu versions. • CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, and CVE-2026-42311 were published on May 9, 2026. • Users of Ubuntu 25.10 and 26.04 LTS are urged to update their systems immediately.

ThreatCluster AI

Timeline

2026-05-09
CVE-2026-42308 published
A vulnerability in Pillow allows large glyph advance values to cause crashes, leading to denial of service.
Ubuntu
2026-05-09
CVE-2026-42309 published
Pillow's handling of nested coordinate lists can lead to crashes, affecting Ubuntu 25.10 and 26.04 LTS.
Ubuntu
2026-05-09
CVE-2026-42310 published
Malformed PDF files can cause Pillow to use excessive resources, leading to denial of service.
Ubuntu
2026-05-09
CVE-2026-42311 published
Certain malformed PSD files can cause Pillow to crash or execute arbitrary code, affecting Ubuntu 25.10 and 26.04 LTS.
Ubuntu
2026-06-08
Ubuntu releases USN-8399-1
Ubuntu issued a security notice addressing multiple vulnerabilities in Pillow, urging users to update their systems.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story