PT-2026-7243 · Libpng+4 · Libpng+4

·

CVE-2026-25646

·

Published

2026-01-01

·

Updated

2026-07-23

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libpng versions prior to 1.6.55
Description An out-of-bounds read heap buffer overflow exists in the png set quantize() API function. The issue occurs when the function is called without a histogram and the palette contains more than twice the maximum number of colors supported by the user's display. Under these conditions, certain palettes can trigger an infinite loop that reads beyond the end of an internal heap-allocated buffer. Specially crafted PNG files that are valid according to the PNG specification can trigger this flaw, potentially leading to denial-of-service crashes, information disclosure, or arbitrary code execution.
Recommendations Update libpng to version 1.6.55. As a temporary workaround, restrict the use of the png set quantize() function until the update is applied.

Exploit

Fix

RCE

DoS

Heap Based Buffer Overflow

Out of bounds Read

Buffer Over-read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:3031
ALSA-2026:3405
ALSA-2026:3551
ALSA-2026:4306
ALSA-2026:4728
ALSA-2026:6439
ALSA-2026:6445
AZL-77409
AZL-77441
AZL-77457
AZL-77460
AZL-77463
AZL-77466
AZL-77468
AZL-77471
AZL-77474
AZL-77477
AZL-77480
BDU:2026-01774
CLEANSTART-2026-AO11810
CLEANSTART-2026-CC73064
CLEANSTART-2026-DW56632
CLEANSTART-2026-EN67837
CLEANSTART-2026-GV99300
CLEANSTART-2026-JR82778
CLEANSTART-2026-KB52131
CLEANSTART-2026-LT34061
CLEANSTART-2026-NH93073
CLEANSTART-2026-OF88781
CLEANSTART-2026-PN81558
CLEANSTART-2026-PX93187
CLEANSTART-2026-QC20347
CLEANSTART-2026-QT07988
CLEANSTART-2026-RR82368
CLEANSTART-2026-TX47991
CLEANSTART-2026-VG07087
CLEANSTART-2026-VG64236
CLEANSTART-2026-WA05811
CLEANSTART-2026-YP34235
CVE-2026-25646
ECHO-6445-7D7C-0289
GHSA-G8HP-MQ4H-RQM3
JLSEC-2026-11
MGASA-2026-0038
MGASA-2026-0096
OPENSUSE-SU-2026:10188-1
OPENSUSE-SU-2026:11265-1
OPENSUSE-SU-2026:20378-1
RHSA-2026:3031
RHSA-2026:3405
RHSA-2026:3551
RHSA-2026:3573
RHSA-2026:3574
RHSA-2026:3575
RHSA-2026:3576
RHSA-2026:3577
RHSA-2026:3968
RHSA-2026:3969
RHSA-2026:4221
RHSA-2026:4222
RHSA-2026:4306
RHSA-2026:4728
RHSA-2026:4729
RHSA-2026:4730
RHSA-2026:4731
RHSA-2026:4732
RHSA-2026:4756
RHSA-2026:6439
RHSA-2026:6445
RHSA-2026:6466
RHSA-2026:6467
RHSA-2026:6468
RHSA-2026:6469
RHSA-2026:6732
RHSA-2026:7032
RHSA-2026:7033
RHSA-2026:7034
RHSA-2026:7035
RHSA-2026:7036
RHSA-2026:9254
RHSA-2026:9683
RHSA-2026:9686
RHSA-2026:9689
RSEC-2026-1
SUSE-SU-2026:0583-1
SUSE-SU-2026:0596-1
SUSE-SU-2026:0597-1
SUSE-SU-2026:0598-1
SUSE-SU-2026:0599-1
SUSE-SU-2026:20523-1
SUSE-SU-2026:20530-1
SUSE-SU-2026:20750-1
SUSE-SU-2026:2878-1
SUSE-SU-2026:3039-1
USN-8035-1
USN-8039-1
USN-8081-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Libpng