---
id: CVE-2025-48379
title: Pillow is a Python imaging library
summary: >-
  Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there
  is a heap buffer overflow when writing a sufficiently large (>64k encoded with
  default settings) image in the DDS format due to writing into a buffer without
  …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-122
vendor: python
product: pillow
affected:
  - pillow = 11.2.1
published: '2025-07-01'
updated: '2026-06-17'
sourceUpdated: '2026-06-17T09:29:34.693'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48379'
references:
  - url: >-
      https://github.com/python-pillow/Pillow/commit/ef98b3510e3e4f14b547762764813d7e5ca3c5a4
    label: security-advisories@github.com
  - url: 'https://github.com/python-pillow/Pillow/pull/9041'
    label: security-advisories@github.com
  - url: 'https://github.com/python-pillow/Pillow/releases/tag/11.3.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/python-pillow/Pillow/security/advisories/GHSA-xg8h-j46f-w952
    label: security-advisories@github.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48379.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-48379'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2375795'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-48379'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-48379'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15839'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15838'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15840'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15842'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15837'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15836'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15841'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15843'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15867'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15832'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-07-01T19:42:09.269034Z'
ingestedAt: '2026-09-14T14:06:11.550Z'
epss: 0.00297
epssPercentile: 0.19967
patched:
  - enterprise_linux_ai 1.5
---

## Overview

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.

## Affected

- `pillow = 11.2.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2025:15839** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15839)
- **RHSA-2025:15838** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15838)
- **RHSA-2025:15840** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15840)
- **RHSA-2025:15842** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15842)
- **RHSA-2025:15837** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15837)
- **RHSA-2025:15836** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15836)
- **RHSA-2025:15841** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15841)
- **RHSA-2025:15843** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15843)
- **RHSA-2025:15867** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15867)
- **RHSA-2025:15832** · Red Hat · fixed in: Red Hat Enterprise Linux AI 1.5 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15832)
- **Red Hat VEX** · Important · affected: OpenShift Lightspeed, Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) · no fix planned: Red Hat Enterprise Linux AI (RHEL AI), OpenShift Lightspeed, Red Hat AI Inference Server · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-48379.json)
