[CLSA-2026:1771840259] libpng: Fix of CVE-2026-25646
Type:
security
Severity:
Important
Release date:
2026-02-23 09:51:04 UTC
Description:
- CVE-2026-25646: fix out-of-bounds read and potential heap buffer overflow in png_set_quantize() caused by stale palette indices during color pruning
Updated packages:
  • libpng-1.6.37-12.el9_2.tuxcare.els6.i686.rpm
    sha:607bc5820ebda4e56818b112c320e53b1cb0a2e0359c0afa57d5174e76e0d49e
  • libpng-1.6.37-12.el9_2.tuxcare.els6.x86_64.rpm
    sha:0debfd9da77438a0c1683458ac84b71c8a451dca289f9681de61c8ba07f584b2
  • libpng-devel-1.6.37-12.el9_2.tuxcare.els6.i686.rpm
    sha:be5003c70cb899d0723b613dd2d5115d316500efa10ba06302c5e2d112f3f1c7
  • libpng-devel-1.6.37-12.el9_2.tuxcare.els6.x86_64.rpm
    sha:b5af3229cddabc941784d9d78d9e76f6a33a41a467489ad1535e56743f48fe92
  • libpng-static-1.6.37-12.el9_2.tuxcare.els6.x86_64.rpm
    sha:c9f9c613fef3846bd442229a525af7a8243f7d2c70eae4ee761ee4b8f83cc66a
  • libpng-tools-1.6.37-12.el9_2.tuxcare.els6.x86_64.rpm
    sha:d3bd158cd70c817691a886440a4ca821a6fd9b119bdfb0e9da897704f031046b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.