CVE-2026-22695
EUVD-2026-242012.01.2026, 23:15
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.51 to 1.6.53, there is a heap buffer over-read in the libpng simplified API function png_image_finish_read when processing interlaced 16-bit PNGs with 8-bit output format and non-minimal row stride. This is a regression introduced by the fix for CVE-2025-65018. This vulnerability is fixed in 1.6.54.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| libpng | libpng | 1.6.51 ≤ 𝑥 < 1.6.54 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libpng16-16 |
| ||||||||||||||||
| libpng16-16-32bit |
| ||||||||||||||||
| libpng16-compat-devel |
| ||||||||||||||||
| libpng16-devel |
|
Red Hat Enterprise Linux Releases
Red Hat Product | |||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libpng |
| ||||||||||||||||||
| libpng-devel |
| ||||||||||||||||||
| mingw32-libpng |
| ||||||||||||||||||
| mingw32-libpng-static |
| ||||||||||||||||||
| mingw64-libpng |
| ||||||||||||||||||
| mingw64-libpng-static |
|
Common Weakness Enumeration