- What: Security update for Python Pillow library
- Impact: Red Hat Enterprise Linux 8.8 systems
Red Hat Product Errata RHSA-2026:48759 - Security Advisory Issued: 2026-07-30 Updated: 2026-07-30 RHSA-2026:48759 - Security Advisory Overview Updated Packages Synopsis Important: python-pillow security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for python-pillow is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Python is an interpreted, interactive, object-oriented programming language, which includes modules, classes, exceptions, very high level dynamic data types and dynamic typing. Python supports interfaces to many system calls and libraries, as well as to various windowing systems. Security Fix(es): python-pillow: Pillow: Denial of Service via crafted BDF font file (CVE-2026-55379) python-pillow: Pillow: Denial of Service via crafted GD 2.x image file (CVE-2026-55380) python-pillow: Pillow: Denial of Service via crafted PCF font data (CVE-2026-54059) python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 x86_64 Red Hat Enterprise Linux Server - TUS 8.8 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64 Fixes BZ - 2497452 - CVE-2026-55379 python-pillow: Pillow: Denial of Service via crafted BDF font file BZ - 2497455 - CVE-2026-55380 python-pillow: Pillow: Denial of Service via crafted GD 2.x image file BZ - 2497464 - CVE-2026-54059 python-pillow: Pillow: Denial of Service via crafted PCF font data BZ - 2497466 - CVE-2026-54060 python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files CVEs CVE-2026-54059 CVE-2026-54060 CVE-2026-55379 CVE-2026-55380 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Life Cycle Long Life 8.8 SRPM python-pillow-5.1.1-20.el8_8.src.rpm SHA-256: 335c3eb99eda4aab7c88c79619b63b4ae262e7b7e1269594330deeed230a6072 x86_64 python-pillow-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 6eeb718686fe212f6a5a8792556817ca54cc2f0040d31cb7dca1885882a4bd09 python-pillow-debugsource-5.1.1-20.el8_8.x86_64.rpm SHA-256: 8131287eb5cd438c8b764cb3e8a63eafdcb9a13be9b2775582bcec87f8f42162 python3-pillow-5.1.1-20.el8_8.x86_64.rpm SHA-256: 01e31064eb3e31a63aff1a185304b4f30b2bcdf28c3e1c3e5a2e2de1dc457ebf python3-pillow-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 4eaf9456150afe368472f0c3e219dbb34e9f3729aa1c9272fa4d472a1109d03d python3-pillow-tk-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 12d34de5569fea6a9807e0da169f973c4e4c3d43e05904abfed64e353165cc4e Red Hat Enterprise Linux Server - TUS 8.8 SRPM python-pillow-5.1.1-20.el8_8.src.rpm SHA-256: 335c3eb99eda4aab7c88c79619b63b4ae262e7b7e1269594330deeed230a6072 x86_64 python-pillow-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 6eeb718686fe212f6a5a8792556817ca54cc2f0040d31cb7dca1885882a4bd09 python-pillow-debugsource-5.1.1-20.el8_8.x86_64.rpm SHA-256: 8131287eb5cd438c8b764cb3e8a63eafdcb9a13be9b2775582bcec87f8f42162 python3-pillow-5.1.1-20.el8_8.x86_64.rpm SHA-256: 01e31064eb3e31a63aff1a185304b4f30b2bcdf28c3e1c3e5a2e2de1dc457ebf python3-pillow-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 4eaf9456150afe368472f0c3e219dbb34e9f3729aa1c9272fa4d472a1109d03d python3-pillow-tk-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 12d34de5569fea6a9807e0da169f973c4e4c3d43e05904abfed64e353165cc4e Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 SRPM python-pillow-5.1.1-20.el8_8.src.rpm SHA-256: 335c3eb99eda4aab7c88c79619b63b4ae262e7b7e1269594330deeed230a6072 ppc64le python-pillow-debuginfo-5.1.1-20.el8_8.ppc64le.rpm SHA-256: 5d4f1d538304b55b843633bf027b49737efc31d18c8721760d544dd5b2465d2e python-pillow-debugsource-5.1.1-20.el8_8.ppc64le.rpm SHA-256: c89a1a18024e4d1b4357d0892f02ab685288993af504cc6d87aa0decc1e7dbcc python3-pillow-5.1.1-20.el8_8.ppc64le.rpm SHA-256: 4c6c4479452ed4e44b4052864b446fadd153509e6ac754e899836e4057d1979d python3-pillow-debuginfo-5.1.1-20.el8_8.ppc64le.rpm SHA-256: a6f191383b41af07798ef52f3cdf3cf81ad38e434a9502cf9e62bb9bc4b25911 python3-pillow-tk-debuginfo-5.1.1-20.el8_8.ppc64le.rpm SHA-256: f5c6e2e5c1a4cf320ada5479aaba4faf590163d04f1dddd9f101c7ba399559ce Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 SRPM python-pillow-5.1.1-20.el8_8.src.rpm SHA-256: 335c3eb99eda4aab7c88c79619b63b4ae262e7b7e1269594330deeed230a6072 x86_64 python-pillow-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 6eeb718686fe212f6a5a8792556817ca54cc2f0040d31cb7dca1885882a4bd09 python-pillow-debugsource-5.1.1-20.el8_8.x86_64.rpm SHA-256: 8131287eb5cd438c8b764cb3e8a63eafdcb9a13be9b2775582bcec87f8f42162 python3-pillow-5.1.1-20.el8_8.x86_64.rpm SHA-256: 01e31064eb3e31a63aff1a185304b4f30b2bcdf28c3e1c3e5a2e2de1dc457ebf python3-pillow-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 4eaf9456150afe368472f0c3e219dbb34e9f3729aa1c9272fa4d472a1109d03d python3-pillow-tk-debuginfo-5.1.1-20.el8_8.x86_64.rpm SHA-256: 12d34de5569fea6a9807e0da169f973c4e4c3d43e05904abfed64e353165cc4e The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .