PT-2025-47832 · Sony+10 · Playstation 4+11

Published

2025-11-22

·

Updated

2026-06-01

·

CVE-2025-65018

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions libpng versions 1.6.0 through 1.6.50 libpng1.6 (affected versions not specified)
Description The libpng library contains a heap buffer overflow issue in the png image finish read function when processing 16-bit interlaced PNGs with 8-bit output format. This can occur when handling specially crafted PNG files, potentially leading to memory corruption, arbitrary code execution, or denial of service. The vulnerability is triggered via the png combine row function. Approximately 600 dependent packages in Ubuntu may be affected. The PlayStation 4 (PS4) and PlayStation 5 (PS5) are also potentially affected, with versions PS5 12.20 and PS4 13.02 theoretically vulnerable.
Recommendations Upgrade to libpng version 1.6.51 or later. For Debian oldstable distribution (bookworm), upgrade to libpng1.6 version 1.6.39-2+deb12u1 or later. For Debian stable distribution (trixie), upgrade to libpng1.6 version 1.6.48-1+deb13u1 or later.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2026:0125
ALSA-2026:0237
ALSA-2026:0238
ALSA-2026:0241
ALSA-2026:0927
ALSA-2026:0928
ALSA-2026:0932
ALSA-2026:0933
ASB-A-463998243
AZL-70850
AZL-70853
AZL-70874
AZL-70877
AZL-70891
AZL-70900
AZL-70912
AZL-70925
AZL-70978
BDU:2025-14613
CVE-2025-65018
DLA-4396-1
DSA-6076-1
ECHO-4A92-1299-0EC1
GHSA-7WV6-48J4-HJ3G
MGASA-2025-0314
MGASA-2026-0024
OESA-2025-2763
OPENSUSE-SU-2025:15781-1
OPENSUSE-SU-2026:20017-1
RHSA-2026:0125
RHSA-2026:0210
RHSA-2026:0211
RHSA-2026:0212
RHSA-2026:0216
RHSA-2026:0234
RHSA-2026:0237
RHSA-2026:0238
RHSA-2026:0241
RHSA-2026:0313
RHSA-2026:0321
RHSA-2026:0322
RHSA-2026:0323
RHSA-2026:0847
RHSA-2026:0927
RHSA-2026:0928
RHSA-2026:0932
RHSA-2026:0933
RHSA-2026:6732
SUSE-SU-2025:21217-1
SUSE-SU-2025:21220-1
SUSE-SU-2025:4436-1
SUSE-SU-2025:4494-1
SUSE-SU-2025:4533-1
SUSE-SU-2026:20030-1
SUSE-SU-2026:20073-1
USN-7924-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Playstation 4
Playstation 5
Red Hat
Red Os
Rocky Linux
Ubuntu
Libpng