Home / mailings [SECURITY] [DSA 6357-1] pillow security update
Posted on 21 June 2026
Debian Security Advisory- -------------------------------------------------------------------------
Debian Security Advisory DSA-6357-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
June 21, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : pillow
CVE ID : CVE-2026-42308 CVE-2026-42310 CVE-2026-42311
Multiple security vulnerabilities have been discovered in Pillow, a
Python imaging library, which could result in denial of service or the
execution of arbitrary code if malformed files are processed.
For the stable distribution (trixie), these problems have been fixed in
version 11.1.0-5+deb13u3.
We recommend that you upgrade your pillow packages.
For the detailed security status of pillow please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/pillow
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
