It was discovered that Pillow incorrectly handled large glyph advance values in fonts. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. (CVE-2026-42308) It was discovered that Pillow incorrectly handled nested coordinate lists in certain APIs. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42309) It was discovered that Pillow incorrectly handled certain malformed PDF files. An attacker could possibly use this issue to cause Pillow to use excessive resources, leading to a denial of service. (CVE-2026-42310) It was discovered that Pillow incorrectly handled certain malformed PSD files. An attacker could possibly use this issue to cause Pillow to crash, resulting in a denial of service, or to execute arbitrary code. This issue only affected Ubuntu 25.10 and Ubuntu 26.04 LTS. (CVE-2026-42311)
Four denial-of-service vulnerabilities (CVE-2026-42308 through CVE-2026-42311, CVSS 5.5 MEDIUM) were discovered in the Pillow library, triggered by processing malicious fonts, nested coordinate lists, malformed PDFs, or malformed PSD files, with one PSD flaw potentially allowing arbitrary code execution on specific Ubuntu releases. Affected versions are python pillow < 12.2.0, with CVE-2026-42309 affecting >= 11.2.1 < 12.2.0 and CVE-2026-42310 affecting >= 4.2.0 < 12.2.0. The fix for all issues is to upgrade to Pillow version 12.2.0.