Skip to content

fix(python-pillow): pin-forward to f43 for 1 CVEs#17286

Draft
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-python-pillow
Draft

fix(python-pillow): pin-forward to f43 for 1 CVEs#17286
tobiasb-ms wants to merge 1 commit into
tomls/base/mainfrom
tobiasb-ms/cve-fix-python-pillow

Conversation

@tobiasb-ms
Copy link
Copy Markdown
Contributor

CVE Pin-Forward: python-pillow

Pins python-pillow to Fedora f43 HEAD (c3200ba) to pick up
1 CVE patches added upstream.

CVEs Resolved

CVE Severity Status
CVE-2026-40192 High Tracked

Fedora Spec Delta

Old commit: 2a9c1d2
New commit: c3200ba

New patches:

  • https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628.patch

Pin locks/python-pillow.lock to Fedora f43 HEAD to pick up
CVE-specific patches added upstream.

CVEs resolved (1 tracked, 0 additional):

  Tracked:
    CVE-2026-40192 (High)

Fedora f43 spec delta (2a9c1d2..c3200ba):
  + https://github.com/python-pillow/Pillow/commit/3cb854e8b2bab43f40e342e665f9340d861aa628.patch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant