PT-2026-7243 · Libpng+4 · Libpng+4

Pwnalone

·

Published

2026-01-01

·

Updated

2026-04-12

·

CVE-2026-25646

CVSS v4.0

8.3

High

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions libpng versions prior to 1.6.55
Description LIBPNG is a library used by applications to read, create, and manipulate PNG raster image files. A flaw exists in the png set quantize() function that can lead to a denial-of-service condition or potentially arbitrary code execution. This issue is triggered when the function is called without a histogram and with a palette that exceeds twice the maximum number of colors supported by the user’s display. The vulnerability stems from an out-of-bounds read within the function, caused by specially crafted, yet valid, PNG files. The issue has been present in the library for approximately 30 years. The png set quantize() function is susceptible to a heap buffer overflow.
Recommendations Versions prior to 1.6.55 should be upgraded to version 1.6.55 or later.

Exploit

Fix

DoS

RCE

Heap Based Buffer Overflow

Buffer Over-read

Weakness Enumeration

Related Identifiers

ALSA-2026:3031
ALSA-2026:3405
ALSA-2026:3551
ALSA-2026:4306
ALSA-2026:4728
ALSA-2026:6439
ALSA-2026:6445
AZL-77409
AZL-77441
AZL-77457
AZL-77460
AZL-77463
AZL-77466
AZL-77468
AZL-77471
AZL-77474
AZL-77477
AZL-77480
BDU:2026-01774
CVE-2026-25646
ECHO-6445-7D7C-0289
GHSA-G8HP-MQ4H-RQM3
MGASA-2026-0038
MGASA-2026-0096
OPENSUSE-SU-2026:10188-1
OPENSUSE-SU-2026:20378-1
RHSA-2026:3031
RHSA-2026:3405
RHSA-2026:3551
RHSA-2026:3573
RHSA-2026:3574
RHSA-2026:3575
RHSA-2026:3576
RHSA-2026:3577
RHSA-2026:3968
RHSA-2026:3969
RHSA-2026:4221
RHSA-2026:4222
RHSA-2026:4306
RHSA-2026:4728
RHSA-2026:4729
RHSA-2026:4730
RHSA-2026:4731
RHSA-2026:4732
RHSA-2026:4756
RHSA-2026:6439
RHSA-2026:6445
RHSA-2026:6466
RHSA-2026:6467
RHSA-2026:6468
RHSA-2026:6469
RHSA-2026:6732
RHSA-2026:7032
RHSA-2026:7033
RHSA-2026:7034
RHSA-2026:7035
RHSA-2026:7036
RHSA-2026:9254
RHSA-2026:9686
RSEC-2026-1
SUSE-SU-2026:0583-1
SUSE-SU-2026:0596-1
SUSE-SU-2026:0597-1
SUSE-SU-2026:0598-1
SUSE-SU-2026:0599-1
SUSE-SU-2026:20523-1
SUSE-SU-2026:20530-1
SUSE-SU-2026:20750-1
USN-8035-1
USN-8039-1
USN-8081-1

Affected Products

Linuxmint
Red Os
Rocky Linux
Ubuntu
Libpng