Red Hat Product Errata RHSA-2026:48021 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:48021 - Security Advisory Overview Updated Packages Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): Pillow: Pillow: Native heap out-of-bounds write (CVE-2026-59197) Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image (CVE-2026-54058) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for x86_64 8 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 8 ppc64le Red Hat CodeReady Linux Builder for ARM 64 8 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2500043 - CVE-2026-59197 Pillow: Pillow: Native heap out-of-bounds write BZ - 2500057 - CVE-2026-54058 Pillow: Pillow: Memory disclosure or denial of service via crafted McIdas AREA image CVEs CVE-2026-54058 CVE-2026-59197 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM python-pillow-5.1.1-23.el8_10.src.rpm SHA-256: e78e0735b8cb2746dafc394a01bd3ea527ba0c6f304c3cf623cd5f53904f22db x86_64 python-pillow-debuginfo-5.1.1-23.el8_10.x86_64.rpm SHA-256: 8f89bdf50b56cd4720c19b0f7abfb4c819c94fd5f9d3cfb1534e629c8de23f58 python-pillow-debugsource-5.1.1-23.el8_10.x86_64.rpm SHA-256: efa3e286672be890651919009ff6aa44092bbf8742be6c25a652e40b85eed37d python3-pillow-5.1.1-23.el8_10.x86_64.rpm SHA-256: 2bbbab7e25d071b10bf25f1c1137d49187e3de1f35c86f8e128ba45debc2d4c4 python3-pillow-debuginfo-5.1.1-23.el8_10.x86_64.rpm SHA-256: e074493bec54b836fd13844c1aff2f791897b69d845c37c53d7acf9a2fa7fe07 python3-pillow-tk-debuginfo-5.1.1-23.el8_10.x86_64.rpm SHA-256: 1f295664f68eb65f9afc0f71a133a522f67b7e34d2164778a13a0eff30e5618c Red Hat Enterprise Linux for IBM z Systems 8 SRPM python-pillow-5.1.1-23.el8_10.src.rpm SHA-256: e78e0735b8cb2746dafc394a01bd3ea527ba0c6f304c3cf623cd5f53904f22db s390x python-pillow-debuginfo-5.1.1-23.el8_10.s390x.rpm SHA-256: 681e703c3dc1d7a4512222f41a04f5bda23db573d8c048d2bc0d367345ba6584 python-pillow-debugsource-5.1.1-23.el8_10.s390x.rpm SHA-256: af08e147ede771e49727c5f2ec77198e1769c51c8a6dbbcdf9b4b429b514d098 python3-pillow-5.1.1-23.el8_10.s390x.rpm SHA-256: 9b6cd5d2ecb195a41fcec0d3c3d48e39c0fddc1108d64bc8ba309cd89be447c0 python3-pillow-debuginfo-5.1.1-23.el8_10.s390x.rpm SHA-256: 170029590562fca2e152abce21320773270aeda485d36e643aba6fbc7148a0f5 python3-pillow-tk-debuginfo-5.1.1-23.el8_10.s390x.rpm SHA-256: 576e1fdab301a66ebf2b2cbef55eacb84ed9bd2c388355dfd71160d6576f3e79 Red Hat Enterprise Linux for Power, little endian 8 SRPM python-pillow-5.1.1-23.el8_10.src.rpm SHA-256: e78e0735b8cb2746dafc394a01bd3ea527ba0c6f304c3cf623cd5f53904f22db ppc64le python-pillow-debuginfo-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 03e5dfe4b912381391d5561673f8ea17a70760196ca62a4ed34b4f43b5a46889 python-pillow-debugsource-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 486f373fa56a9e018a4a153ecd520f0c4b89cf794dbe2bec4dc7c97edecc03e7 python3-pillow-5.1.1-23.el8_10.ppc64le.rpm SHA-256: bf19ee379469f864ce05d611a342932d1fe940e2bb7e21aeae118a52a4ca37a8 python3-pillow-debuginfo-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 14d04ba7d1ccbfca0c3339a8f6efafab500ddad8c8a5440f35df57f556d1626c python3-pillow-tk-debuginfo-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 184d53552e00952fb254832c49f843d602486b58266f0a4e345d15e12ae45fc2 Red Hat Enterprise Linux for ARM 64 8 SRPM python-pillow-5.1.1-23.el8_10.src.rpm SHA-256: e78e0735b8cb2746dafc394a01bd3ea527ba0c6f304c3cf623cd5f53904f22db aarch64 python-pillow-debuginfo-5.1.1-23.el8_10.aarch64.rpm SHA-256: 46267331f41ac17ef4d7085543f981ca323dfe0f26343ad8132d2a6893ab7e25 python-pillow-debugsource-5.1.1-23.el8_10.aarch64.rpm SHA-256: a75714573eb4c06a6af2f78a84cca3cd693fe143cc68f78a6d514141da97cd1a python3-pillow-5.1.1-23.el8_10.aarch64.rpm SHA-256: 5e23a1abcd47f3805104405061c101c1442e6dcfc7386793798340ce807cc181 python3-pillow-debuginfo-5.1.1-23.el8_10.aarch64.rpm SHA-256: f76ea1799e24d53cfee16dfab999784ba260ce46364a267ecc7dc629a9afc359 python3-pillow-tk-debuginfo-5.1.1-23.el8_10.aarch64.rpm SHA-256: 1d172c18fb3d2323be62ddb6a7cfa00100d1f1ec10250470bcc13566577c0f88 Red Hat CodeReady Linux Builder for x86_64 8 SRPM x86_64 python-pillow-debuginfo-5.1.1-23.el8_10.i686.rpm SHA-256: c3f83f30b40bf2db9185f09c30312b1925e27ff7fa1c15b03be639092131dfce python-pillow-debuginfo-5.1.1-23.el8_10.x86_64.rpm SHA-256: 8f89bdf50b56cd4720c19b0f7abfb4c819c94fd5f9d3cfb1534e629c8de23f58 python-pillow-debugsource-5.1.1-23.el8_10.i686.rpm SHA-256: 6fab6391bf9a0c5bc354ef66ca1c2fac1b08ea460d4d00af9d6331e23c5aaa49 python-pillow-debugsource-5.1.1-23.el8_10.x86_64.rpm SHA-256: efa3e286672be890651919009ff6aa44092bbf8742be6c25a652e40b85eed37d python3-pillow-5.1.1-23.el8_10.i686.rpm SHA-256: 102c3c5fb13fd3a4fc51943a66061dfd22e1a0fb755876b62265ea4b9f78565b python3-pillow-debuginfo-5.1.1-23.el8_10.i686.rpm SHA-256: d6156d87d35943ba2d090da1722333cb3f100b560353a6197379428a973394a0 python3-pillow-debuginfo-5.1.1-23.el8_10.x86_64.rpm SHA-256: e074493bec54b836fd13844c1aff2f791897b69d845c37c53d7acf9a2fa7fe07 python3-pillow-devel-5.1.1-23.el8_10.i686.rpm SHA-256: 36d79c8a7c5baeec8c0d509bfa4d257da9d341cf28d659554f3fb440492b9935 python3-pillow-devel-5.1.1-23.el8_10.x86_64.rpm SHA-256: d1c64857d1278bd106ea66203714d384aeade1abb8c53a884000a271da4238f2 python3-pillow-doc-5.1.1-23.el8_10.noarch.rpm SHA-256: c0111d6ed9a7f1e26456ebee3adeaf3ae9963dc2cb399349b1602d852d03bea0 python3-pillow-tk-5.1.1-23.el8_10.x86_64.rpm SHA-256: ab2dab998bf49d601ca0eeaf67380c5c8150cfea6ae4d7b3314a90cbc7c6ad2b python3-pillow-tk-debuginfo-5.1.1-23.el8_10.i686.rpm SHA-256: 45c534a5fa736608269ede40594a3ffbe4abee3a8eceb1ef672d78e0ce2827ee python3-pillow-tk-debuginfo-5.1.1-23.el8_10.x86_64.rpm SHA-256: 1f295664f68eb65f9afc0f71a133a522f67b7e34d2164778a13a0eff30e5618c Red Hat CodeReady Linux Builder for Power, little endian 8 SRPM ppc64le python-pillow-debuginfo-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 03e5dfe4b912381391d5561673f8ea17a70760196ca62a4ed34b4f43b5a46889 python-pillow-debugsource-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 486f373fa56a9e018a4a153ecd520f0c4b89cf794dbe2bec4dc7c97edecc03e7 python3-pillow-debuginfo-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 14d04ba7d1ccbfca0c3339a8f6efafab500ddad8c8a5440f35df57f556d1626c python3-pillow-devel-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 515ed4f80676bfe3be1a2ac5d3f90e5788ef3da198c0775f4c676646124b372c python3-pillow-doc-5.1.1-23.el8_10.noarch.rpm SHA-256: c0111d6ed9a7f1e26456ebee3adeaf3ae9963dc2cb399349b1602d852d03bea0 python3-pillow-tk-5.1.1-23.el8_10.ppc64le.rpm SHA-256: c1358a0cf3a31167e246bf4bde9daa8377755344d86fadf13fa5108ddab79185 python3-pillow-tk-debuginfo-5.1.1-23.el8_10.ppc64le.rpm SHA-256: 184d53552e00952fb254832c49f843d602486b58266f0a4e345d15e12ae45fc2 Red Hat CodeReady Linux Builder for ARM 64 8 SRPM aarch64 python-pillow-debuginfo-5.1.1-23.el8_10.aarch64.rpm SHA-256: 46267331f41ac17ef4d7085543f981ca323dfe0f26343ad8132d2a6893ab7e25 python-pillow-debugsource-5.1.1-23.el8_10.aarch64.rpm SHA-256: a75714573eb4c06a6af2f78a84cca3cd693fe143cc68f78a6d514141da97cd1a python3-pillow-debuginfo-5.1.1-23.el8_10.aarch64.rpm SHA-256: f76ea1799e24d53cfee16dfab999784ba260ce46364a267ecc7dc629a9afc359 python3-pillow-devel-5.1.1-23.el8_10.aarch64.rpm SHA-256: 9d4d774ee58133807dfc4a2df1758ae023744742fed67562eac48da44e434d56 python3-pillow-doc-5.1.1-23.el8_10.noarch.rpm SHA-256: c0111d6ed9a7f1e26456ebee3adeaf3ae9963dc2cb399349b1602d852d03bea0 python3-pillow-tk-5.1.1-23.el8_10.aarch64.rpm SHA-256: dc0c987c5fec452e5bfa97ab96436af57d60f758c938fa00f654d51dee63edb9 python3-pillow-tk-debuginfo-5.1.1-23.el8_10.aarch64.rpm SHA-256: 1d172c18fb3d2323be62ddb6a7cfa00100d1f1ec10250470bcc13566577c0f88 Red Hat CodeReady Linux Builder for IBM z Systems 8 SRPM s390x python-pillow-debuginfo-5.1.1-23.el8_10.s390x.rpm SHA-256: 681e703c3dc1d7a4512222f41a04f5bda23db573d8c048d2bc0d367345ba6584 python-pillow-debugsource-5.1.1-23.el8_10.s390x.rpm SHA-256: af08e147ede771e49727c5f2ec77198e1769c51c8a6dbbcdf9b4b429b514d098 python3-pillow-debuginfo-5.1.1-23.el8_10.s390x.rpm SHA-256: 170029590562fca2e152abce21320773270aeda485d36e643aba6fbc7148a0f5 python3-pillow-devel-5.1.1-23.el8_10.s390x.rpm SHA-256: 87bcda604902529a1d174099c344ddfbdd91530126f1fb506f5f8c79a2b05b96 python3-pillow-doc-5.1.1-23
This update addresses two vulnerabilities in the python-pillow library: a native heap out-of-bounds write (CVE-2026-59197, CVSS 8.2 HIGH) and a memory disclosure/denial of service flaw via crafted McIdas AREA images (CVE-2026-54058). The heap out-of-bounds write affects pillow versions prior to 12.3.0, which should be upgraded to version 12.3.0 or later to remediate.