Executive brief
Pillow, a widely used Python library for image processing, contains a vulnerability that can be triggered when processing Adobe Photoshop (PSD) files. An attacker could provide a specially crafted image file that, when opened by an application using Pillow, causes the program to crash or behave unexpectedly. This could lead to a denial-of-service condition, impacting the availability of services that automate image handling or thumbnail generation.
Technical details
An out-of-bounds (OOB) write vulnerability (CWE-787) exists in Pillow's PSD image decoding logic. The flaw is rooted in a failure to validate tile extents, specifically allowing negative x or y offsets during the decoding or encoding process. An attacker can exploit this by providing a malformed PSD file, which triggers a write outside the intended buffer when processed via `Image.open()`. This can result in a process crash (DoS) or potentially memory corruption. The issue is resolved in version 12.1.1 by implementing checks to ensure tile extents do not use negative offsets. A temporary workaround involves using the `formats` parameter in `Image.open()` to disable PSD support.
Affected products
- python-pillow Pillow >= 10.3.0, < 12.1.1
Timeline
- 2026-02-11: disclosed
- 2026-02-11: patched: Fixed in version 12.1.1
- 2026-02-11: advisory
References
- https://github.com/python-pillow/Pillow/commit/9000313cc5d4a31bdcdd6d7f0781101abab553aa
- https://github.com/python-pillow/Pillow/security/advisories/GHSA-cfh3-3jmp-rvhc
- http://www.openwall.com/lists/oss-security/2026/02/12/1
- https://access.redhat.com/errata/RHSA-2026:10184
- https://access.redhat.com/errata/RHSA-2026:14873
- https://access.redhat.com/errata/RHSA-2026:14874
- https://access.redhat.com/errata/RHSA-2026:16174