Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-06669

Опубликовано: 26 мар. 2026
Источник: fstec
CVSS3: 7.6
CVSS2: 9
EPSS Низкий

Описание

Уязвимость библиотеки libpng связана с отсутствием проверки достаточного количества входных пикселей при обработке последней частичной порции в оптимизированном для ARM/AArch64 Neon пути расширения палитры. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, раскрыть защищаемую информации и выполнить отказ в обслуживании

Вендор

Novell Inc.
Сообщество свободного программного обеспечения
ООО «Ред Софт»
Red Hat Inc.
АО «ИВК»
Guy Eric Schalnat Andreas Dilger Glenn Randers-Pehrson

Наименование ПО

openSUSE Tumbleweed
Debian GNU/Linux
РЕД ОС
Red Hat Enterprise Linux
АЛЬТ СП 10
SUSE Liberty Linux
OpenSUSE Leap
Suse Linux Enterprise Desktop
Suse Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Micro
OPENJDK ELS
libpng

Версия ПО

- (openSUSE Tumbleweed)
12 (Debian GNU/Linux)
7.3 (РЕД ОС)
9 (Red Hat Enterprise Linux)
8.2 Advanced Update Support (Red Hat Enterprise Linux)
8.4 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
- (АЛЬТ СП 10)
9 (SUSE Liberty Linux)
8 (SUSE Liberty Linux)
15.6 (OpenSUSE Leap)
9.0 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.6 Update Services for SAP Solutions (Red Hat Enterprise Linux)
8.6 Telecommunications Update Service (Red Hat Enterprise Linux)
8.6 Advanced Mission Critical Update Support (Red Hat Enterprise Linux)
7 LTSS (SUSE Liberty Linux)
9.4 Extended Update Support (Red Hat Enterprise Linux)
15 SP7 (Suse Linux Enterprise Desktop)
15 SP7 (Suse Linux Enterprise Server)
15 SP7 (SUSE Linux Enterprise Server for SAP Applications)
10 (Red Hat Enterprise Linux)
8.8 Telecommunications Update Service (Red Hat Enterprise Linux)
8.8 Update Services for SAP Solutions (Red Hat Enterprise Linux)
9.2 Update Services for SAP Solutions (Red Hat Enterprise Linux)
13 (Debian GNU/Linux)
6.0 (SUSE Linux Micro)
6.1 (SUSE Linux Micro)
16.0 (SUSE Linux Enterprise Server for SAP Applications)
8.4 Extended Update Support Long-Life Add-On (Red Hat Enterprise Linux)
16.0 (Suse Linux Enterprise Server)
9.6 Extended Update Support (Red Hat Enterprise Linux)
16.0 (OpenSUSE Leap)
8.0 (РЕД ОС)
6.2 (SUSE Linux Micro)
10.0 Extended Update Support (Red Hat Enterprise Linux)
10 (SUSE Liberty Linux)
11.0.31 (OPENJDK ELS)
15 SP6-LTSS (Suse Linux Enterprise Server)
от 1.6.36 до 1.6.55 (libpng)

Тип ПО

Операционная система
Прикладное ПО информационных систем

Операционные системы и аппаратные платформы

Novell Inc. openSUSE Tumbleweed -
Сообщество свободного программного обеспечения Debian GNU/Linux 12
ООО «Ред Софт» РЕД ОС 7.3
Red Hat Inc. Red Hat Enterprise Linux 9
Red Hat Inc. Red Hat Enterprise Linux 8.2 Advanced Update Support
Red Hat Inc. Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
АО «ИВК» АЛЬТ СП 10 -
Novell Inc. SUSE Liberty Linux 9
Novell Inc. SUSE Liberty Linux 8
Novell Inc. OpenSUSE Leap 15.6
Red Hat Inc. Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 8.6 Telecommunications Update Service
Red Hat Inc. Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
Novell Inc. SUSE Liberty Linux 7 LTSS
Red Hat Inc. Red Hat Enterprise Linux 9.4 Extended Update Support
Novell Inc. Suse Linux Enterprise Desktop 15 SP7
Novell Inc. Suse Linux Enterprise Server 15 SP7
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 15 SP7
Red Hat Inc. Red Hat Enterprise Linux 10
Red Hat Inc. Red Hat Enterprise Linux 8.8 Telecommunications Update Service
Red Hat Inc. Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
Red Hat Inc. Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
Сообщество свободного программного обеспечения Debian GNU/Linux 13
Novell Inc. SUSE Linux Micro 6.0
Novell Inc. SUSE Linux Micro 6.1
Novell Inc. SUSE Linux Enterprise Server for SAP Applications 16.0
Red Hat Inc. Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
Novell Inc. Suse Linux Enterprise Server 16.0
Red Hat Inc. Red Hat Enterprise Linux 9.6 Extended Update Support
Novell Inc. OpenSUSE Leap 16.0
ООО «Ред Софт» РЕД ОС 8.0
Novell Inc. SUSE Linux Micro 6.2
Red Hat Inc. Red Hat Enterprise Linux 10.0 Extended Update Support
Novell Inc. SUSE Liberty Linux 10
Novell Inc. Suse Linux Enterprise Server 15 SP6-LTSS

Уровень опасности уязвимости

Высокий уровень опасности (базовая оценка CVSS 2.0 составляет 9)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,6)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/pnggroup/libpng/commit/7734cda20cf1236aef60f3bbd2267c97bbb40869
https://github.com/pnggroup/libpng/commit/aba9f18eba870d14fb52c5ba5d73451349e339c3
https://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-33636
Для программных продуктов Novell Inc.:
https://www.suse.com/security/cve/CVE-2026-33636.html
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/DSA-6189-1
Для ОС АЛЬТ СП 10: установка обновления из публичного репозитория программного средства: https://altsp.su/obnovleniya-bezopasnosti/
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=&q=CVE-2026-33636

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 44%
0.00585
Низкий

7.6 High

CVSS3

9 Critical

CVSS2

Связанные уязвимости

CVSS3: 7.6
redos
2 месяца назад

Уязвимость libpng12

CVSS3: 7.6
redos
2 месяца назад

Уязвимость libpng

CVSS3: 7.6
redos
2 месяца назад

Уязвимость mingw-libpng

CVSS3: 7.6
redos
2 месяца назад

Уязвимость libpng15

CVSS3: 7.6
ubuntu
4 месяца назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.

EPSS

Процентиль: 44%
0.00585
Низкий

7.6 High

CVSS3

9 Critical

CVSS2