Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-55379

CVE-2026-55379: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.5

    High [CVE-2026-55379] Denial of Service via crafted BDF font file

    CVE-2026-55379Source published Source updated

    Pillow is a Python imaging library. Prior to 12.3.0, PIL/BdfFontFile.py bdf_char() read the BBX width and height field from a BDF font file and passed attacker-controlled dimensions to Image.new() without calling Image._decompression_bomb_check(), bypassing Pillow's documented decompression bomb protection and allowing excessive memory allocation. This issue is fixed in version 12.3.0. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by providing a specially crafted BDF font file. The library's image processing function fails to properly validate dimensions from the font file, bypassing a critical security check designed to prevent excessive memory usage. This oversight can lead to the system consuming an unreasonable amount of memory, making it unavailable…

    Affected products in this advisory
    • Red Hat Ansible Automation Platform 2.5 for RHEL 8
    • Red Hat Ansible Automation Platform 2.5 for RHEL 9
    • Red Hat Ansible Automation Platform 2.6 for RHEL 9
    • Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support

    28 more entries in the full advisory.

    Source-reported affected versions
    • < 12.3.0
    Source-reported fixed versions
    • 12.3.0
    • python3.12-pillow-0:12.3.0-1.el8ap
    • python3.12-pillow-0:12.3.0-1.el9ap
    • python-pillow-0:5.1.1-22.el8_10

    46 more entries in the full advisory.

    Mitigation guidance
    • Do not load BDF font files from untrusted sources. Applications that only process standard image formats (PNG, JPEG, etc.) and do not use BdfFontFile or ImageFont.load() with BDF files are not affected.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery