Skip to main content
EPSS 0.3%top 80%

CVE-2025-48379: CWE-122: Heap-based Buffer Overflow in python-pillow Pillow

0
High
Published: 07/03/2025 (07/03/2025, 05:57:27 UTC)
Source: CVE Database V5
Vendor/Project: python-pillow
Product: Pillow

Description

Pillow is a Python imaging library. In versions 11.2.0 to before 11.3.0, there is a heap buffer overflow when writing a sufficiently large (>64k encoded with default settings) image in the DDS format due to writing into a buffer without checking for available space. This only affects users who save untrusted data as a compressed DDS image. This issue has been patched in version 11.3.0.

CVSS v3.1

Score 7.1high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected software

Affected versions
>=11.2.0 <11.3.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/08/2026, 13:26:42 UTC

Technical Analysis

CVE-2025-48379 is a heap-based buffer overflow vulnerability (CWE-122) in the Pillow library versions 11.2.0 through before 11.3.0. The overflow happens when writing large DDS format images (>64k) because the code writes into a buffer without verifying available space. This vulnerability only impacts scenarios where untrusted data is saved as compressed DDS images. The flaw was patched in Pillow version 11.3.0.

Potential Impact

The vulnerability can lead to heap corruption when processing large DDS images, potentially causing denial of service or arbitrary code execution. The CVSS score of 7.1 (high) reflects the potential for high impact on integrity and availability. Confidentiality impact is not indicated. Exploitation requires local privileges and no user interaction, with low attack complexity.

Mitigation Recommendations

Users should upgrade to Pillow version 11.3.0 or later where the vulnerability is patched. Avoid saving untrusted data as compressed DDS images if upgrading is not immediately possible.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
GitHub_M
Date Reserved
2025-05-19T15:46:00.396Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 68642b616f40f0eb72904a39

Added to database: 07/01/2025, 18:39:29 UTC

Last enriched: 09/08/2026, 13:26:42 UTC

Last updated: 09/10/2026, 22:04:57 UTC

Views: 1266

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses