High severity7.5NVD Advisory· Published Mar 3, 2021· Updated Jun 17, 2026
CVE-2021-27921
CVE-2021-27921
Description
Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation can be very large.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
PillowPyPI | < 8.1.2 | 8.1.2 |
Affected products
15- Pillow/Pillowdescription
- osv-coords10 versionspkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2015.5pkg:pypi/pillowpkg:rpm/almalinux/python3-pillowpkg:bitnami/pillowpkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Tumbleweedpkg:rpm/suse/python-Pillow&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/python-Pillow&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/python-Pillow&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/opensuse/python-Pillow&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/python-CairoSVG&distro=openSUSE%20Leap%2015.2
< 7.2.0-150300.3.15.1+ 9 more
- (no CPE)range: < 7.2.0-150300.3.15.1
- (no CPE)range: < 8.1.2
- (no CPE)range: < 5.1.1-16.el8
- (no CPE)range: < 8.1.1
- (no CPE)range: < 8.3.2-1.2
- (no CPE)range: < 7.2.0-150300.3.15.1
- (no CPE)range: < 5.2.0-3.8.1
- (no CPE)range: < 5.2.0-3.8.1
- (no CPE)range: < 8.3.1-lp152.5.3.1
- (no CPE)range: < 2.5.1-lp152.2.3.1
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
19- github.com/advisories/GHSA-f4w8-cv6p-x6r5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-27921ghsaADVISORY
- pillow.readthedocs.io/en/stable/releasenotes/8.1.1.htmlnvdRelease NotesVendor AdvisoryWEB
- security.gentoo.org/glsa/202107-33nvdThird Party AdvisoryWEB
- github.com/pypa/advisory-database/tree/main/vulns/pillow/PYSEC-2021-40.yamlghsaWEB
- github.com/python-pillow/Pillow/commit/756fff33128a0b643d10518a26ad04b726dd8973ghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JUghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2MLghsaWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JUghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2MLghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZghsaWEB
- pillow.readthedocs.io/en/stable/releasenotes/8.1.2.htmlnvdWEB
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/S7G44Z33J4BNI2DPDROHWGVG2U7ZH5JU/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/TQQY6472RX4J2SUJENWDZAWKTJJGP2ML/nvd
- lists.fedoraproject.org/archives/list/[email protected]/message/ZTSY25UJU7NJUFHH3HWT575LT4TDFWBZ/nvd
News mentions
0No linked articles in our index yet.