Launch Week Day 1: Announcing Security Design Review
HIGH 7.1 PyPI

Pillow vulnerability can cause write buffer overflow on BCn encoding

GHSA-xg8h-j46f-w952 · BIT-pillow-2025-48379 · CVE-2025-48379 · PYSEC-2025-61

Published · Modified

Description

There is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space.

This only affects users who save untrusted data as a compressed DDS image.

  • Unclear how large the potential write could be. It is likely limited by process segfault, so it's not necessarily deterministic. It may be practically unbounded.
  • Unclear if there's a restriction on the bytes that could be emitted. It's likely that the only restriction is that the bytes would be emitted in chunks of 8 or 16.

This was introduced in Pillow 11.2.0 when the feature was added.

Ready to move

Start Securing

Free, no credit card | First findings in minutes