PT-2025-47831 · Libpng+9 · Libpng+9

Published

2025-05-26

·

Updated

2026-06-01

·

CVE-2025-64720

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:S/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions libpng versions 1.6.0 through 1.6.50 libpng1.6 (affected versions not specified)
Description The libpng PNG library contains a flaw that could lead to information leaks, denial of service, or potentially the execution of arbitrary code when processing specially crafted images. The issue is an out-of-bounds read vulnerability in the png image read composite function when processing palette images with the PNG FLAG OPTIMIZE ALPHA flag enabled. The vulnerability stems from incorrect background compositing during premultiplication within the png init read transformations function, violating a required component invariant.
Recommendations Upgrade libpng1.6 packages to version 1.6.39-2+deb12u1 for Debian bookworm. Upgrade libpng1.6 packages to version 1.6.48-1+deb13u1 for Debian trixie. Upgrade libpng to version 1.6.51 or later.

Exploit

Fix

RCE

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2026:0125
ALSA-2026:0237
ALSA-2026:0238
ALSA-2026:0241
ALSA-2026:0927
ALSA-2026:0928
ALSA-2026:0932
ALSA-2026:0933
ASB-A-463995203
AZL-70847
AZL-70868
AZL-70883
AZL-70888
AZL-70921
AZL-70928
AZL-70972
BDU:2026-02925
CVE-2025-64720
DLA-4396-1
DSA-6076-1
ECHO-AD7D-93E1-B804
GHSA-HFC7-PH9C-WCWW
MGASA-2025-0314
MGASA-2026-0024
OESA-2025-2763
OPENSUSE-SU-2025:15781-1
OPENSUSE-SU-2026:20017-1
RHSA-2026:0125
RHSA-2026:0210
RHSA-2026:0211
RHSA-2026:0212
RHSA-2026:0216
RHSA-2026:0234
RHSA-2026:0237
RHSA-2026:0238
RHSA-2026:0241
RHSA-2026:0251
RHSA-2026:0313
RHSA-2026:0321
RHSA-2026:0322
RHSA-2026:0323
RHSA-2026:0847
RHSA-2026:0927
RHSA-2026:0928
RHSA-2026:0932
RHSA-2026:0933
RHSA-2026:6732
SUSE-SU-2025:21217-1
SUSE-SU-2025:21220-1
SUSE-SU-2025:4436-1
SUSE-SU-2025:4494-1
SUSE-SU-2025:4533-1
SUSE-SU-2026:20030-1
SUSE-SU-2026:20073-1
USN-7924-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Libpng
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu