[CLSA-2026:1771839565] libpng: Fix of CVE-2026-25646
Type:
security
Severity:
Important
Release date:
2026-02-23 09:39:29 UTC
Description:
- CVE-2026-25646: fix out-of-bounds read and potential heap buffer overflow in png_set_quantize() caused by stale palette indices during color pruning
Updated packages:
  • libpng-1.6.37-12.el9_6.tuxcare.els6.i686.rpm
    sha:ff1f7d13a8207898fc38c06107ee8599deeedd3ad05a7d345e0cc877de6a3ffc
  • libpng-1.6.37-12.el9_6.tuxcare.els6.x86_64.rpm
    sha:df025f4ace1c398fe83dbff7cfdfec92d4a26941f614c3bafda17366f0b267db
  • libpng-devel-1.6.37-12.el9_6.tuxcare.els6.i686.rpm
    sha:98b3536243868ed610959e9b83c5acd5cdc9e75cb8a9afa84fc616fad1d087c7
  • libpng-devel-1.6.37-12.el9_6.tuxcare.els6.x86_64.rpm
    sha:d52ff849936356b8fbd27408b698023f7a87696323c040a481dc9d88e55bcd93
  • libpng-static-1.6.37-12.el9_6.tuxcare.els6.x86_64.rpm
    sha:3e6bd3f7a463835d502811155f570a30a76d4e24480f0e46e8f31ebcb28f2f68
  • libpng-tools-1.6.37-12.el9_6.tuxcare.els6.x86_64.rpm
    sha:036ca9bc407d5417355a1c2cbcdc5036557b6313c38cf18768d6cb86279ce54b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.