PT-2026-30205 · Julia · Libpng Jll

Published

2026-03-24

·

Updated

2026-03-24

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png write image 16bit and png write image 8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-8

Affected Products

Libpng Jll