Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-25646

Опубликовано: 10 фев. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.1

Описание

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps/noble

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
upstream

released

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
questing

not-affected

code not present
upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

released

1.2.50-1ubuntu2.14.04.3+esm1
esm-infra/xenial

released

1.2.54-1ubuntu1.1+esm2
jammy

DNE

noble

DNE

questing

DNE

upstream

needed

Показывать по

РелизСтатусПримечание
devel

released

1.6.55-1
esm-apps/xenial

released

1.6.20-2ubuntu0.1~esm3
esm-infra/bionic

released

1.6.34-1ubuntu0.18.04.2+esm2
esm-infra/focal

released

1.6.37-2ubuntu0.1~esm2
jammy

released

1.6.37-3ubuntu0.4
noble

released

1.6.43-5ubuntu0.5
questing

released

1.6.50-1ubuntu0.4
upstream

released

1.6.55

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
jammy

not-affected

uses system libpng
noble

not-affected

code not present
questing

not-affected

code not present
upstream

needs-triage

Показывать по

EPSS

Процентиль: 21%
0.00068
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
около 2 месяцев назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.

CVSS3: 8.1
nvd
около 2 месяцев назад

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.

CVSS3: 8.1
debian
около 2 месяцев назад

LIBPNG is a reference library for use in applications that read, creat ...

suse-cvrf
около 1 месяца назад

Security update for libpng12

suse-cvrf
около 1 месяца назад

Security update for libpng12

EPSS

Процентиль: 21%
0.00068
Низкий

8.1 High

CVSS3