CVE-2026-42308

Red Hat Security Advisory: Red Hat AI Inference Server 3.3.3 (CUDA)

mediumEPSS 0.1%

Description

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0.

Metrics

Severity
medium
no public PoC known
5.5
Source: nvd-v3
1.6 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-05-11 15:49 UTC
CWE-190

Weakness classes (CWE)

  • CWE-190Base

    Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-07-24 21:10 UTC· nvd@nist.gov
    • Translation: Title: Pillow de python-pillow, Description: Pillow es una biblioteca de procesamiento de imágenes de Python. Antes de la versión 12.2.0, si una fuente avanza para cada glifo una cantidad excesivamente grande, cuando Pillow rastrea la posición actual, esto puede provocar un desbordamiento de entero. Este problema ha sido parcheado en la versión 12.2.0.

Affected operating systems

  • linux

    debian / debian_linux11.0

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux6.0

  • linux

    redhat / enterprise_linux7.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_server_aus8.2

  • linux

    redhat / enterprise_linux_server_aus8.4

  • linux

    redhat / enterprise_linux_server_tus8.8

  • linux

    ubuntu / giflibjammy

  • linux

    ubuntu / giflibnoble

  • linux

    ubuntu / giflibresolute

  • linux

    canonical / ubuntu_linux20.04

  • linux

    canonical / ubuntu_linux22.04

  • linux

    canonical / ubuntu_linux24.04

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    pillow10.3.0

  • bitnami

    pillow11.2.1

  • bitnami

    pillow4.2.0

  • bitnami

    pillow

  • canonical

    ubuntu_linux

  • gnome

    gdk-pixbuf

  • libarchive

    libarchive

  • nghttp2

    nghttp21.68.1

  • openbsd

    openssh

  • openexr

    openexr3.3.0 – 3.3.8

  • openexr

    openexr3.4.0 – 3.4.6

  • openexr

    openexr3.2.6

  • pypi

    cbor21.0.0

  • pypi

    cbor21.1.0

  • pypi

    cbor22.0.0

  • pypi

    cbor23.0.0

  • pypi

    cbor23.0.1

  • pypi

    cbor23.0.2

  • pypi

    cbor23.0.3

  • pypi

    cbor23.0.4

  • pypi

    cbor24.0.0

  • pypi

    cbor24.0.1

  • pypi

    cbor24.1.0

  • pypi

    cbor24.1.1

References & sources

Linked CVEs

IDCVE-2026-42308