ALAS2-2026-3312


Amazon Linux 2 Security Advisory: ALAS2-2026-3312
Advisory Released Date: 2026-05-26
Advisory Updated Date: 2026-05-26
Severity: Important

Issue Overview:

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer overflow. This issue has been patched in version 12.2.0. (CVE-2026-42308)

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code execution. This issue has been patched in version 12.2.0. (CVE-2026-42311)


Affected Packages:

python-pillow


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update python-pillow or yum update --advisory ALAS2-2026-3312 to update your system.

New Packages:
aarch64:
    python-pillow-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
    python-pillow-devel-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
    python-pillow-doc-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
    python-pillow-sane-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
    python-pillow-tk-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64
    python-pillow-debuginfo-2.0.0-23.gitd1c6db8.amzn2.0.18.aarch64

i686:
    python-pillow-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
    python-pillow-devel-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
    python-pillow-doc-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
    python-pillow-sane-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
    python-pillow-tk-2.0.0-23.gitd1c6db8.amzn2.0.18.i686
    python-pillow-debuginfo-2.0.0-23.gitd1c6db8.amzn2.0.18.i686

src:
    python-pillow-2.0.0-23.gitd1c6db8.amzn2.0.18.src

x86_64:
    python-pillow-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
    python-pillow-devel-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
    python-pillow-doc-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
    python-pillow-sane-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
    python-pillow-tk-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64
    python-pillow-debuginfo-2.0.0-23.gitd1c6db8.amzn2.0.18.x86_64