Skip to content
Multiple Pillow Vulnerabilities Affect Ubuntu Users

Multiple Pillow Vulnerabilities Affect Ubuntu Users

First seen 8 Jun 2026, 21:23 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 9, 2026 at 21:00 UTC

On June 8, 2026, Ubuntu released USN-8399-1 addressing several vulnerabilities in the Pillow library. These vulnerabilities could allow attackers to exploit large glyph advance values, nested coordinate lists, and malformed PDF and PSD files, potentially leading to denial of service attacks. The affected versions include Ubuntu 25.10 and Ubuntu 26.04 LTS. Specific CVEs include CVE-2026-42308, CVE-2026-42309, CVE-2026-42310, and CVE-2026-42311, all published on May 9, 2026. Users are advised to update their systems to mitigate these risks. The vulnerabilities could allow excessive resource usage or crashes, impacting service availability. The issues highlight the importance of timely software updates for maintaining security.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 103d ago How this analysis works

Timeline

2026-05-09
CVE-2026-42308 published
A vulnerability in Pillow allows large glyph advance values to cause crashes, leading to denial of service.
Ubuntu
2026-05-09
CVE-2026-42309 published
Pillow's handling of nested coordinate lists can lead to crashes, affecting Ubuntu 25.10 and 26.04 LTS.
Ubuntu
2026-05-09
CVE-2026-42310 published
Malformed PDF files can cause Pillow to use excessive resources, leading to denial of service.
Ubuntu
2026-05-09
CVE-2026-42311 published
Certain malformed PSD files can cause Pillow to crash or execute arbitrary code, affecting Ubuntu 25.10 and 26.04 LTS.
Ubuntu
2026-06-08
Ubuntu releases USN-8399-1
Ubuntu issued a security notice addressing multiple vulnerabilities in Pillow, urging users to update their systems.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-42308 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed