Security News

Cybersecurity news aggregator

🔓
MEDIUM Vulnerabilities Ubuntu Security

USN-8047-1: Pillow vulnerability

  • What: A vulnerability in Pillow allows an attacker to cause a denial of service or potentially execute arbitrary code by opening a specially crafted PSD image.
  • Impact: Systems using Pillow to process PSD images are vulnerable to crashing or arbitrary code execution.
Read Full Article →

Ubuntu Security Notices USN-8047-1 USN-8047-1: Pillow vulnerability Publication date 17 February 2026 Overview Pillow could be made to crash or run programs if it opened a specially crafted file. Releases 25.10 Packages pillow - Python Imaging Library Details Yarden Porat discovered that Pillow incorrectly handled certain malformed PSD images. An attacker could use this issue to cause Pillow to crash, resulting in a denial of service, or possibly execute arbitrary code. Yarden Porat discovered that Pillow incorrectly handled certain malformed PSD images. An attacker could use this issue to cause Pillow to crash, resulting in a denial of service, or possibly execute arbitrary code. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 25.10 questing python3-pil – 11.3.0-1ubuntu1.1 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-25990 CVE-2026-25990

Share this article