PT-2026-28502 · Libpng+4 · Libpng+4

Amemoyoi

·

Published

2026-01-01

·

Updated

2026-05-26

·

CVE-2026-33636

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions LIBPNG versions 1.6.36 through 1.6.55
Description An out-of-bounds read and write exists in the ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying if sufficient input pixels remain. Because the implementation operates backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer, leading to an out-of-bounds read, and writes expanded pixel data to those same underflowed positions, causing an out-of-bounds write. This issue is reachable through the normal decoding of attacker-controlled PNG input if Neon is enabled.
Recommendations Update to version 1.6.56.

Exploit

Fix

RCE

Out of bounds Read

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:14790
ALSA-2026:14791
ALSA-2026:7671
ALSA-2026:7672
ALSA-2026:8052
ALSA-2026:8459
ALSA-2026:9345
ALSA-2026:9638
ALSA-2026:9693
BDU:2026-06669
CVE-2026-33636
ECHO-42F8-ED7B-D9F3
GHSA-WJR5-C57X-95M2
MGASA-2026-0070
OESA-2026-1852
OPENSUSE-SU-2026:10451-1
OPENSUSE-SU-2026:20466-1
RHSA-2026:11805
RHSA-2026:11813
RHSA-2026:12264
RHSA-2026:13342
RHSA-2026:13412
RHSA-2026:13533
RHSA-2026:13582
RHSA-2026:13583
RHSA-2026:13596
RHSA-2026:13600
RHSA-2026:13665
RHSA-2026:13682
RHSA-2026:13683
RHSA-2026:13922
RHSA-2026:13977
RHSA-2026:14223
RHSA-2026:14303
RHSA-2026:14790
RHSA-2026:14791
RHSA-2026:15889
RHSA-2026:17524
RHSA-2026:17567
RHSA-2026:17603
RHSA-2026:17642
RHSA-2026:17685
RHSA-2026:6732
RHSA-2026:7671
RHSA-2026:7672
RHSA-2026:8052
RHSA-2026:8459
RHSA-2026:9254
RHSA-2026:9345
RHSA-2026:9638
RHSA-2026:9693
SUSE-SU-2026:1368-1
SUSE-SU-2026:21000-1
SUSE-SU-2026:21038-1
SUSE-SU-2026:21067-1
SUSE-SU-2026:21138-1
USN-8251-1

Affected Products

Libpng
Linuxmint
Red Os
Rocky Linux
Ubuntu