Amazon Linux 2 Security Advisory: ALAS2-2026-3312
Advisory Released Date: 2026-05-26
Advisory Updated Date: 2026-05-26
Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0. (CVE-2026-42308)
Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0. (CVE-2026-42311)
Affected Packages:
python-pillow
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update python-pillow or yum update --advisory ALAS2-2026-3312 to update your system.
aarch64:
python-pillow-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
python-pillow-devel-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
python-pillow-doc-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
python-pillow-sane-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
python-pillow-tk-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
python-pillow-debuginfo-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
i686:
python-pillow-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
python-pillow-devel-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
python-pillow-doc-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
python-pillow-sane-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
python-pillow-tk-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
python-pillow-debuginfo-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
src:
python-pillow-2.0.0-23.gitd1c6db8.amzn2.0.18.src
x86_64:
python-pillow-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
python-pillow-devel-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
python-pillow-doc-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
python-pillow-sane-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
python-pillow-tk-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
python-pillow-debuginfo-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64