{"id":"CVE-2025-48379","title":"Pillow is a Python imaging library","summary":"Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without …","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-122"],"vendor":"python","product":"pillow","affected":["pillow = 11.2.1"],"published":"2025-07-01","updated":"2026-06-17","sourceUpdated":"2026-06-17T09:29:34.693","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-48379","references":[{"url":"https://github.com/python-pillow/Pillow/commit/ef98b3510e3e4f14b547762764813d7e5ca3c5a4","label":"security-advisories@github.com"},{"url":"https://github.com/python-pillow/Pillow/pull/9041","label":"security-advisories@github.com"},{"url":"https://github.com/python-pillow/Pillow/releases/tag/11.3.0","label":"security-advisories@github.com"},{"url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-xg8h-j46f-w952","label":"security-advisories@github.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48379.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-48379"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2375795"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-48379"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48379"},{"url":"https://access.redhat.com/errata/RHSA-2025:15839"},{"url":"https://access.redhat.com/errata/RHSA-2025:15838"},{"url":"https://access.redhat.com/errata/RHSA-2025:15840"},{"url":"https://access.redhat.com/errata/RHSA-2025:15842"},{"url":"https://access.redhat.com/errata/RHSA-2025:15837"},{"url":"https://access.redhat.com/errata/RHSA-2025:15836"},{"url":"https://access.redhat.com/errata/RHSA-2025:15841"},{"url":"https://access.redhat.com/errata/RHSA-2025:15843"},{"url":"https://access.redhat.com/errata/RHSA-2025:15867"},{"url":"https://access.redhat.com/errata/RHSA-2025:15832"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2025-07-01T19:42:09.269034Z"},"ingestedAt":"2026-09-14T14:06:11.550Z","epss":0.00297,"epssPercentile":0.22555,"patched":["enterprise_linux_ai 1.5"],"slug":"CVE-2025-48379","body":"## Overview\n\nPillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.\n\n## Affected\n\n- `pillow = 11.2.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2025:15839** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15839)\n- **RHSA-2025:15838** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15838)\n- **RHSA-2025:15840** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15840)\n- **RHSA-2025:15842** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15842)\n- **RHSA-2025:15837** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15837)\n- **RHSA-2025:15836** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15836)\n- **RHSA-2025:15841** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15841)\n- **RHSA-2025:15843** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15843)\n- **RHSA-2025:15867** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15867)\n- **RHSA-2025:15832** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15832)\n- **Red Hat VEX** · Important · affected: OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) · no fix planned: Red Hat Enterprise Linux AI (RHEL AI), OpenShift Lightspeed, Red Hat AI Inference Server · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48379.json)","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}