{"id":"CVE-2026-54060","title":"python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files (CVE-2026-54060)","summary":"A flaw was found in Pillow, a Python imaging library. When processing a specially crafted font file, the library's font compilation function does not adequately check for excessive memory allocation. This oversight allows a remote attacker…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"vendor","cwe":"CWE-1050","vendor":"Red Hat","product":"Red Hat OpenShift AI 3.4","affected":["exploit_intelligence","lightspeed_core","openshift_lightspeed","ai_inference_server","ansible_automation_platform 2","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","satellite 6","ansible_automation_platform_2_5_for_rhel 8","satellite_6_16_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_4","enterprise_linux_appstream_eus_extension_v_8_4","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_crb_v_8","ai_inference_server 3.2","ai_inference_server 3.3","ai_inference_server 3.4","ansible_automation_platform 2.6","ansible_automation_platform 2.7","enterprise_linux_ai 3.3","openshift_ai 3.4","quay 3.10","quay 3.12","quay 3.15","quay 3.16","quay 3.9"],"patched":["ansible_automation_platform_2_5_for_rhel 8","satellite_6_16_for_rhel 8","ansible_automation_platform_2_5_for_rhel 9","ansible_automation_platform_2_6_for_rhel 9","satellite_6_16_for_rhel 9","satellite_6_17_for_rhel 9","satellite_6_18_for_rhel 9","satellite_6_19_for_rhel 9","enterprise_linux_appstream_v_8","enterprise_linux_appstream_aus_v_8_4","enterprise_linux_appstream_eus_extension_v_8_4","enterprise_linux_appstream_aus_v_8_6","enterprise_linux_appstream_eus_extension_v_8_6","enterprise_linux_appstream_e4s_v_8_8","enterprise_linux_appstream_tus_v_8_8","enterprise_linux_crb_v_8","ai_inference_server 3.2","ai_inference_server 3.3","ai_inference_server 3.4","ansible_automation_platform 2.6","ansible_automation_platform 2.7","enterprise_linux_ai 3.3","openshift_ai 3.4","quay 3.10","quay 3.12","quay 3.15","quay 3.16","quay 3.9"],"published":"2026-07-06","updated":"2026-09-21","sourceUpdated":"2026-09-21T16:39:04+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54060.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54060.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-54060"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2497466"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-54060"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54060"},{"url":"https://github.com/python-pillow/Pillow/blob/main/docs/releasenotes/12.3.0.rst"},{"url":"https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d"},{"url":"https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2"},{"url":"https://access.redhat.com/errata/RHSA-2026:50319"},{"url":"https://access.redhat.com/errata/RHSA-2026:50223"},{"url":"https://access.redhat.com/errata/RHSA-2026:50336"},{"url":"https://access.redhat.com/errata/RHSA-2026:50222"},{"url":"https://access.redhat.com/errata/RHSA-2026:50263"},{"url":"https://access.redhat.com/errata/RHSA-2026:50221"},{"url":"https://access.redhat.com/errata/RHSA-2026:39127"},{"url":"https://access.redhat.com/errata/RHSA-2026:52551"},{"url":"https://access.redhat.com/errata/RHSA-2026:48760"},{"url":"https://access.redhat.com/errata/RHSA-2026:48759"},{"url":"https://access.redhat.com/errata/RHSA-2026:61628"},{"url":"https://access.redhat.com/errata/RHSA-2026:61627"},{"url":"https://access.redhat.com/errata/RHSA-2026:61629"},{"url":"https://access.redhat.com/errata/RHSA-2026:59518"},{"url":"https://access.redhat.com/errata/RHSA-2026:69468"},{"url":"https://access.redhat.com/errata/RHSA-2026:69466"},{"url":"https://access.redhat.com/errata/RHSA-2026:69467"},{"url":"https://access.redhat.com/errata/RHSA-2026:69469"},{"url":"https://access.redhat.com/errata/RHSA-2026:69464"},{"url":"https://access.redhat.com/errata/RHSA-2026:50479"},{"url":"https://access.redhat.com/errata/RHSA-2026:50340"},{"url":"https://access.redhat.com/errata/RHSA-2026:62336"},{"url":"https://access.redhat.com/errata/RHSA-2026:62335"},{"url":"https://access.redhat.com/errata/RHSA-2026:60520"},{"url":"https://access.redhat.com/errata/RHSA-2026:53520"},{"url":"https://access.redhat.com/errata/RHSA-2026:52968"},{"url":"https://access.redhat.com/errata/RHSA-2026:48933"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2026-2254.yaml"},{"url":"https://github.com/python-pillow/Pillow"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00418,"epssPercentile":0.35669,"aliases":["GHSA-5x94-69rx-g8h2","BIT-pillow-2026-54060","PYSEC-2026-2254"],"ecosystem":"pip","ingestedAt":"2026-07-13T18:58:08.562Z","slug":"CVE-2026-54060","body":"## Overview\n\nA flaw was found in Pillow, a Python imaging library. When processing a specially crafted font file, the library's font compilation function does not adequately check for excessive memory allocation. This oversight allows a remote attacker to trigger an unreasonable consumption of system memory, leading to a denial of service (DoS) for the application.\n\n## Vendor advisories\n\n- **RHSA-2026:50319** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50319)\n- **RHSA-2026:50223** · Red Hat · fixed in: Red Hat Satellite 6.16 for RHEL 8, Red Hat Satellite 6.16 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50223)\n- **RHSA-2026:50336** · Red Hat · fixed in: Red Hat Ansible Automation Platform 2.6 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50336)\n- **RHSA-2026:50222** · Red Hat · fixed in: Red Hat Satellite 6.17 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50222)\n- **RHSA-2026:50263** · Red Hat · fixed in: Red Hat Satellite 6.18 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50263)\n- **RHSA-2026:50221** · Red Hat · fixed in: Red Hat Satellite 6.19 for RHEL 9 · released 2026-08-04 · [advisory](https://access.redhat.com/errata/RHSA-2026:50221)\n- **RHSA-2026:39127** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-07-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:39127)\n- **RHSA-2026:52551** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-08-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:52551)\n- **RHSA-2026:48760** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:48760)\n- **RHSA-2026:48759** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-07-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:48759)\n- **RHSA-2026:61628** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61628)\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, Lightspeed Core, OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Red Hat Enterprise Linux AI (RHEL AI) 3, … · no fix planned: Red Hat AI Inference Server, Red Hat Ansible Automation Platform 2, Exploit Intelligence, Lightspeed Core, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-54060.json)\n\n**python-pillow: Pillow: Denial of Service via excessive memory allocation when processing font files** — rated Important by Red Hat. Released 2026-07-06, updated 2026-09-21.\n\nAffected:\n\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n\nFixed:\n\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Satellite 6.16 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Satellite 6.16 for RHEL 9\n- Red Hat Satellite 6.17 for RHEL 9\n- Red Hat Satellite 6.18 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Enterprise Linux AppStream (v. 8)\n- Red Hat Enterprise Linux AppStream AUS (v.8.4)\n- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)\n- Red Hat Enterprise Linux AppStream AUS (v.8.6)\n- Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6)\n- Red Hat Enterprise Linux AppStream E4S (v.8.8)\n- Red Hat Enterprise Linux AppStream TUS (v.8.8)\n- Red Hat Enterprise Linux CRB (v. 8)\n- Red Hat AI Inference Server 3.2\n- Red Hat AI Inference Server 3.3\n- Red Hat AI Inference Server 3.4\n- Red Hat Ansible Automation Platform 2.6\n- Red Hat Ansible Automation Platform 2.7\n- Red Hat Enterprise Linux AI 3.3\n- Red Hat OpenShift AI 3.4\n- Red Hat Quay 3.10\n- Red Hat Quay 3.12\n- Red Hat Quay 3.15\n- Red Hat Quay 3.16\n- Red Hat Quay 3.9\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat Ansible Automation Platform 2\n- Exploit Intelligence\n- Lightspeed Core\n- OpenShift Lightspeed\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n- Red Hat Satellite 6\n\nNot affected:\n\n- Red Hat Ansible Automation Platform 2.6 for RHEL 10\n- Red Hat Ansible Automation Platform 2.5 for RHEL 8\n- Red Hat Satellite 6.16 for RHEL 8\n- Red Hat Ansible Automation Platform 2.5 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6 for RHEL 9\n- Red Hat Satellite 6.16 for RHEL 9\n- Red Hat Satellite 6.17 for RHEL 9\n- Red Hat Satellite 6.18 for RHEL 9\n- Red Hat Satellite 6.19 for RHEL 9\n- Red Hat Ansible Automation Platform 2.6\n\n## Remediation\n\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50319\nBefore applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor detailed instructions how to apply this update, refer to:\n\nhttps://docs.redhat.com/en/documentation/red_hat_satellite/6.16/html/updating_red_hat_satellite/index https://access.redhat.com/errata/RHSA-2026:50223\nFor details on how to apply this update, refer to Ansible Automation Platform documentation. https://access.redhat.com/errata/RHSA-2026:50336\n\n## Package advisory (CVE-2026-54060)\n\nAffected packages:\n\n- `pillow < 12.3.0`\n\nPatched in:\n\n- `pillow 12.3.0`\n\nSource: https://osv.dev/vulnerability/GHSA-5x94-69rx-g8h2","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}