PT-2025-48996 · Libpng+9 · Libpng+9

Published

2025-12-03

·

Updated

2026-04-01

·

CVE-2025-66293

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:P/I:N/A:C
Name of the Vulnerable Software and Affected Versions libpng versions prior to 1.6.52
Description LIBPNG is a library used for reading, creating, and manipulating PNG raster image files. A flaw exists in libpng's simplified API where processing valid palette PNG images with partial transparency and gamma correction can lead to an out-of-bounds read. Specifically, the png sRGB base[512] array can be read beyond its bounds by up to 1012 bytes. The vulnerability occurs due to an issue in libpng's internal state management when handling these types of PNG images. The affected function is png image read composite. The PNG files that trigger this issue are valid according to the PNG specification.
Recommendations Upgrade to libpng version 1.6.52 or later.

Exploit

Fix

DoS

RCE

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:0125
ALSA-2026:0237
ALSA-2026:0238
ALSA-2026:0241
AZL-71246
AZL-71455
AZL-71458
AZL-71461
AZL-71464
AZL-71467
AZL-71470
AZL-71485
AZL-71488
AZL-71491
AZL-71494
AZL-71497
AZL-71644
BDU:2025-15390
CVE-2025-66293
DLA-4396-1
DSA-6076-1
ECHO-91C2-E6D0-2B32
GHSA-9MPM-9PXH-MG4F
MGASA-2025-0323
OESA-2026-1124
OESA-2026-1125
OESA-2026-1126
OESA-2026-1127
OESA-2026-1128
OESA-2026-1129
OPENSUSE-SU-2025:15801-1
OPENSUSE-SU-2026:20017-1
RHSA-2026:0125
RHSA-2026:0210
RHSA-2026:0211
RHSA-2026:0212
RHSA-2026:0216
RHSA-2026:0234
RHSA-2026:0237
RHSA-2026:0238
RHSA-2026:0241
RHSA-2026:0313
RHSA-2026:0321
RHSA-2026:0322
RHSA-2026:0323
RHSA-2026:6732
RHSA-2026:9254
RHSA-2026:9686
SUSE-SU-2025:21217-1
SUSE-SU-2025:21220-1
SUSE-SU-2025:4436-1
SUSE-SU-2025:4494-1
SUSE-SU-2026:0085-1
SUSE-SU-2026:20030-1
SUSE-SU-2026:20073-1
USN-7963-1
USN-8035-1

Affected Products

Alt Linux
Almalinux
Centos
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Ubuntu
Libpng