CVE-2020-11538: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.

In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.

Affected products

  • Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
  • Fedoraproject Fedora: version 31 only; version 32 only
  • Python Pillow: up to and including 7.0.0

Published 2020-06-25. Last modified 2026-06-17.