PT-2026-4944 · Libpng+3 · Libpng+3

Published

2025-01-01

·

Updated

2026-04-14

·

CVE-2025-28162

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions libpng versions 1.6.43 through 1.6.46
Description A buffer overflow issue exists in libpng versions 1.6.43 through 1.6.46. A local attacker can potentially cause a denial of service by exploiting the vulnerability through a specially crafted pngimage. When AddressSanitizer (ASan) is enabled, the program may leak memory in multiple locations, resulting in increased memory usage and potentially causing the program to become unresponsive.
Recommendations Update libpng to a version later than 1.6.46.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-05685
CVE-2025-28162
ECHO-6086-BF4F-3673
OESA-2026-1313
OESA-2026-1314
OESA-2026-1315
OESA-2026-1316
OPENSUSE-SU-2026:20378-1
RHSA-2026:6732
SUSE-SU-2026:0364-1
SUSE-SU-2026:0596-1
SUSE-SU-2026:20523-1
SUSE-SU-2026:20530-1
SUSE-SU-2026:20750-1
USN-7993-1

Affected Products

Linuxmint
Red Os
Ubuntu
Libpng