24h | 7d | 30d

Overview

  • pnggroup
  • libpng

12 Jan 2026
Published
13 Jan 2026
Updated

CVSS v3.1
MEDIUM (6.8)
EPSS
0.01%

KEV

Description

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

Statistics

  • 1 Post

Last activity: 15 hours ago

Bluesky

Profile picture
🚨 CRITICAL: Mageia 9 libpng vulnerabilities CVE-2026-22695 & CVE-2026-22801 allow heap buffer over-read attacks. MGASA-2026-0010 patch now available. Read more: 👉 tinyurl.com/52x7w749 #Security
  • 0
  • 0
  • 0
  • 15h ago
Showing 21 to 21 of 21 CVEs