CVE-2026-25990

Red Hat Security Advisory: Red Hat AI Inference Server 3.2.2 (CUDA)

Description

Pillow is a Python imaging library. From 10.3.0 to before 12.1.1, an out-of-bounds write may be triggered when loading a specially crafted PSD image. This vulnerability is fixed in 12.1.1.

Metrics

Severity
high
no public PoC known
8.6
Source: nvd-v4
30.7 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-02-27 14:54 UTC
CWE-787

Weakness classes (CWE)

  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-10 13:17 UTC· security-advisories@github.com
    • Reference: https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa
    • Reference: https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc
    • Reference: https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa
    • Reference: https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc
  2. CVE Modified2026-09-10 13:17 UTC· af854a3a-2127-422b-91ae-364da2661108
    • Reference: http://www.openwall.com/lists/oss-security/2026/02/12/1
    • Reference: http://www.openwall.com/lists/oss-security/2026/02/12/1
    • Reference Type: http://www.openwall.com/lists/oss-security/2026/02/12/1 Types: Mailing List, Patch, Third Party Advisory
  3. CVE Modified2026-09-10 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/25xxx/CVE-2026-25990.json">CVE-2026-25990</a>
    • Reference: https://access.redhat.com/errata/RHSA-2026:10184
    • Reference: https://access.redhat.com/errata/RHSA-2026:14873
    • Reference: https://access.redhat.com/errata/RHSA-2026:14874
  4. CVE Modified2026-07-21 12:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:42644
    • Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+61)Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+61)
  5. CVE Modified2026-07-20 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Affected: Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+61)Red Hat Ansible Automation Platform 2.5 for RHEL 8, Red Hat Ansible Automation Platform 2.5 for RHEL 9, Red Hat Ansible Automation Platform 2.6 for RHEL 9 (+61)

Affected operating systems

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    ubuntu / gdaltrusty

  • linux

    ubuntu / gdalxenial

  • linux

    ubuntu / golang-go.cryptobionic

  • linux

    ubuntu / golang-go.cryptofocal

  • linux

    ubuntu / golang-go.cryptojammy

  • linux

    ubuntu / golang-go.cryptonoble

  • linux

    ubuntu / golang-go.cryptoquesting

  • linux

    ubuntu / golang-go.cryptoxenial

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • aiohttp

    aiohttp3.13.3

  • anyscale

    ray2.52.0

  • bitnami

    golang1.24.0

  • bitnami

    sqlite

  • Dell

    Secure Connect GatewayAppliance 5.32.00.18

  • go

    github.com/opencontainers/runc1.0.0-rc3

  • go

    github.com/opencontainers/runc1.3.0-rc.1

  • go

    github.com/opencontainers/runc1.4.0-rc.1

  • go

    github.com/sigstore/fulcio

  • go

    golang.org/x/oauth2

  • google

    protobuf33.4

  • IBM

    AIX7.2

  • IBM

    AIX7.3

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • IBM

    DevOps Code ClearCase10.0.1.05

  • IBM

    DevOps Code ClearCase11.0.0.05

  • IBM

    DevOps Code ClearCase9.1.0.10

  • IBM

    MQContainer

  • IBM

    MQOperator

  • IBM

    TXSeriesfor multiplatforms

  • IBM

    VIOS3.1

  • IBM

    VIOS4.1

  • IGEL

    OS11.11.100

  • IGEL

    OS12.7.4

References & sources

Linked CVEs

Show 15 more CVEs
IDCVE-2026-25990