Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-06668

Опубликовано: 26 мар. 2026
Источник: fstec
CVSS3: 7.5
CVSS2: 7.6
EPSS Низкий

Описание

Уязвимость функций png_set_tRNS и png_set_PLTE библиотеки LIBPNG связана с некорректным управлением памятью при освобождении данных. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, получить доступ к освобождённой области памяти, что может привести к выполнению произвольного кода или отказу в обслуживании

Вендор

Red Hat Inc.
ООО «Ред Софт»
Novell Inc.
АО «ИВК»
Guy Eric Schalnat Andreas Dilger Glenn Randers-Pehrson

Наименование ПО

Red Hat Enterprise Linux
РЕД ОС
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Micro
АЛЬТ СП 10
Suse Linux Enterprise Server
OpenSUSE Leap
SUSE Linux Micro
OPENJDK ELS
libpng

Версия ПО

8 (Red Hat Enterprise Linux)
7.3 (РЕД ОС)
15 SP4 (SUSE Linux Enterprise Server for SAP Applications)
5.2 (SUSE Linux Enterprise Micro)
5.3 (SUSE Linux Enterprise Micro)
8.2 Advanced Update Support (Red Hat Enterprise Linux)
15 SP5 (SUSE Linux Enterprise Server for SAP Applications)
5.4 (SUSE Linux Enterprise Micro)
8.4 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
- (АЛЬТ СП 10)
5.5 (SUSE Linux Enterprise Micro)
9.2 Extended Update Support (Red Hat Enterprise Linux)
15 SP4-LTSS (Suse Linux Enterprise Server)
15 SP6 (SUSE Linux Enterprise Server for SAP Applications)
15.6 (OpenSUSE Leap)
9.0 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.6 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.6 Telecommunications Update Service (Red Hat Enterprise Linux)
8.6 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
12 SP5-LTSS (Suse Linux Enterprise Server)
9.4 Extended Update Support (Red Hat Enterprise Linux)
15 SP5-LTSS (Suse Linux Enterprise Server)
10 (Red Hat Enterprise Linux)
6.0 (SUSE Linux Micro)
6.1 (SUSE Linux Micro)
16.0 (SUSE Linux Enterprise Server for SAP Applications)
8.4 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
16.0 (Suse Linux Enterprise Server)
9.6 Extended Update Support (Red Hat Enterprise Linux)
16.0 (OpenSUSE Leap)
8.0 (РЕД ОС)
6.2 (SUSE Linux Micro)
10.0 Extended Update Support (Red Hat Enterprise Linux)
11.0.31 (OPENJDK ELS)
15 SP6-LTSS (Suse Linux Enterprise Server)
от 1.2.1 до 1.6.55 (libpng)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Red Hat Inc. Red Hat Enterprise Linux 8
ООО «Ред Софт» РЕД ОС 7.3
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 15 SP4
Red Hat Inc. Red Hat Enterprise Linux 8.2 Advanced Update Support
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 15 SP5
Red Hat Inc. Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
АО «ИВК» АЛЬТ СП 10 -
Red Hat Inc. Red Hat Enterprise Linux 9.2 Extended Update Support
Novell Inc. Suse Linux Enterprise Server 15 SP4-LTSS
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 15 SP6
Novell Inc. OpenSUSE Leap 15.6
Red Hat Inc. Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Red Hat Inc. Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Novell Inc. Suse Linux Enterprise Server 12 SP5-LTSS
Red Hat Inc. Red Hat Enterprise Linux 9.4 Extended Update Support
Novell Inc. Suse Linux Enterprise Server 15 SP5-LTSS
Red Hat Inc. Red Hat Enterprise Linux 10
Novell Inc. SUSE Linux Micro 6.0
Novell Inc. SUSE Linux Micro 6.1
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 16.0
Red Hat Inc. Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Novell Inc. Suse Linux Enterprise Server 16.0
Red Hat Inc. Red Hat Enterprise Linux 9.6 Extended Update Support
Novell Inc. OpenSUSE Leap 16.0
ООО «Ред Софт» РЕД ОС 8.0
Novell Inc. SUSE Linux Micro 6.2
Red Hat Inc. Red Hat Enterprise Linux 10.0 Extended Update Support
Novell Inc. Suse Linux Enterprise Server 15 SP6-LTSS

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 7,6)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,5)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/pnggroup/libpng/commit/23019269764e35ed8458e517f1897bd3c54820eb
https://github.com/pnggroup/libpng/commit/7ea9eea884a2328cc7fdcb3c0c00246a50d90667
https://github.com/pnggroup/libpng/commit/a3a21443ed12bfa1ef46fa0d4fb2b74a0fa34a25
https://github.com/pnggroup/libpng/commit/c1b0318b393c90679e6fa5bc1d329fd5d5012ec1
https://github.com/pnggroup/libpng/pull/824
https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-33416
Для программных продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2026-33416.html
Для ОС АЛЬТ СП 10: установка обновления из публичного репозитория программного средства: https://altsp.su/obnovleniya-bezopasnosti/
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-33116

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Существует в открытом доступе

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 61%
0.01052
Низкий

7.5 High

CVSS3

7.6 High

CVSS2

Связанные уязвимости

CVSS3: 7.5
redos
2 месяца назад

Уязвимость mingw-libpng

CVSS3: 7.5
redos
2 месяца назад

Уязвимость libpng15

CVSS3: 7.5
redos
2 месяца назад

Уязвимость libpng12

CVSS3: 7.5
redos
2 месяца назад

Уязвимость libpng

CVSS3: 7.5
ubuntu
4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two structs with independent lifetimes. The `trans_alpha` aliasing has been present since at least libpng 1.0, and the `palette` aliasing since at least 1.2.1. Both affect all prior release lines `png_set_tRNS` sets `png_ptr->trans_alpha = info_ptr->trans_alpha` (256-byte buffer) and `png_set_PLTE` sets `info_ptr->palette = png_ptr->palette` (768-byte buffer). In both cases, calling `png_free_data` (with `PNG_FREE_TRNS` or `PNG_FREE_PLTE`) frees the buffer through `info_ptr` while the corresponding `png_ptr` pointer remains dangling. Subsequent row-transform functions dereference and, in some code paths, write to the freed memory. A second call to `png_set_tRNS` or `png_set...

EPSS

Процентиль: 61%
0.01052
Низкий

7.5 High

CVSS3

7.6 High

CVSS2