LIBPNG has an out-of-bounds read in png_image_read_composite
Published Dec 3, 2025
7.1
HIGHCVSS 3.1
EPSS 0.35%
Description
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
Affected products
-
- Version < 1.6.52StatusaffectedConstraints-
- Version
No data.
Red Hat Discovery 2
discovery/discovery-ui-rhel9:1767904573
Fixed · RHSA-2026:0414
Red Hat Enterprise Linux 10
libpng-2:1.6.40-8.el10_1.1
Fixed · RHSA-2026:0237
Red Hat Enterprise Linux 10.0 Extended Update Support
libpng-2:1.6.40-8.el10_0.1
Fixed · RHSA-2026:0212
Red Hat Enterprise Linux 8
libpng-2:1.6.34-9.el8_10
Fixed · RHSA-2026:0241
Red Hat Enterprise Linux 8
mingw-libpng-0:1.6.34-1.el8_10
Fixed · RHSA-2026:0125
Red Hat Enterprise Linux 8.2 Advanced Update Support
libpng-2:1.6.34-8.el8_2.1
Fixed · RHSA-2026:0323
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
libpng-2:1.6.34-8.el8_4.1
Fixed · RHSA-2026:0321
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
libpng-2:1.6.34-8.el8_4.1
Fixed · RHSA-2026:0321
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
libpng-2:1.6.34-8.el8_6.1
Fixed · RHSA-2026:0322
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
libpng-2:1.6.34-8.el8_6.1
Fixed · RHSA-2026:0322
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
libpng-2:1.6.34-8.el8_6.1
Fixed · RHSA-2026:0322
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
libpng-2:1.6.34-8.el8_8.1
Fixed · RHSA-2026:0313
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
libpng-2:1.6.34-8.el8_8.1
Fixed · RHSA-2026:0313
Red Hat Enterprise Linux 9
libpng-2:1.6.37-12.el9_7.1
Fixed · RHSA-2026:0238
Red Hat Enterprise Linux 9
libpng-2:1.6.37-12.el9_7.1
Fixed · RHSA-2026:0238
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
libpng-2:1.6.37-12.el9_0.1
Fixed · RHSA-2026:0234
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
libpng-2:1.6.37-12.el9_2.1
Fixed · RHSA-2026:0216
Red Hat Enterprise Linux 9.4 Extended Update Support
libpng-2:1.6.37-12.el9_4.1
Fixed · RHSA-2026:0211
Red Hat Enterprise Linux 9.6 Extended Update Support
libpng-2:1.6.37-12.el9_6.1
Fixed · RHSA-2026:0210
Red Hat Hardened Images
libpng-main-1.6.56-1.hum1
Fixed · RHSA-2026:6732
Red Hat OpenShift Container Platform 4.12
rhcos-412.86.202603041314-0
Fixed · RHSA-2026:3861
Red Hat OpenShift Container Platform 4.13
rhcos-413.92.202602240113-0
Fixed · RHSA-2026:3415
Red Hat OpenShift Container Platform 4.14
rhcos-414.92.202602171627-0
Fixed · RHSA-2026:2974
Red Hat OpenShift Container Platform 4.15
rhcos-415.92.202603101737-0
Fixed · RHSA-2026:4419
Red Hat OpenShift Container Platform 4.16
rhcos-416.94.202602101357-0
Fixed · RHSA-2026:2659
Red Hat OpenShift Container Platform 4.17
rhcos-417.94.202602090846-0
Fixed · RHSA-2026:2671
Red Hat OpenShift Container Platform 4.18
rhcos-418.94.202602022246-0
Fixed · RHSA-2026:2072
Red Hat OpenShift Container Platform 4.19
rhcos-4.19.9.6.202602112047-0
Fixed · RHSA-2026:2633
Red Hat Enterprise Linux 10
firefox
Not affected
Red Hat Enterprise Linux 10
java-21-openjdk
Not affected
Red Hat Enterprise Linux 10
java-25-openjdk
Not affected
Red Hat Enterprise Linux 10
thunderbird
Not affected
Red Hat Enterprise Linux 6
libpng
Will not fix
Red Hat Enterprise Linux 7
firefox
Not affected
Red Hat Enterprise Linux 7
java-11-openjdk
Not affected
Red Hat Enterprise Linux 7
libpng
Not affected
Red Hat Enterprise Linux 7
libpng12
Not affected
Red Hat Enterprise Linux 8
firefox
Not affected
Red Hat Enterprise Linux 8
java-1.8.0-openjdk
Not affected
Red Hat Enterprise Linux 8
java-17-openjdk
Not affected
Red Hat Enterprise Linux 8
java-21-openjdk
Not affected
Red Hat Enterprise Linux 8
libpng12
Not affected
Red Hat Enterprise Linux 8
libpng15
Not affected
Red Hat Enterprise Linux 8
thunderbird
Not affected
Red Hat Enterprise Linux 9
firefox
Not affected
Red Hat Enterprise Linux 9
java-1.8.0-openjdk
Not affected
Red Hat Enterprise Linux 9
java-17-openjdk
Not affected
Red Hat Enterprise Linux 9
java-21-openjdk
Not affected
Red Hat Enterprise Linux 9
libpng15
Not affected
Red Hat Enterprise Linux 9
thunderbird
Not affected
Red Hat OpenShift Container Platform 4
openshift/ose-rhel-coreos-8
Affected
Red Hat build of OpenJDK 1.8
java-1.8.0-openjdk-portable
Not affected
Red Hat build of OpenJDK 17
java-17-openjdk-portable
Not affected
Red Hat build of OpenJDK 17
java-21-openjdk-portable
Not affected
Red Hat build of OpenJDK 21
java-21-openjdk-portable
Not affected
Red Hat build of OpenJDK 21
java-21-openjdk-portable-rhel7
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1767904573 | Fixed | RHSA-2026:0414 |
| Red Hat Enterprise Linux 10 | libpng-2:1.6.40-8.el10_1.1 | Fixed | RHSA-2026:0237 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | libpng-2:1.6.40-8.el10_0.1 | Fixed | RHSA-2026:0212 |
| Red Hat Enterprise Linux 8 | libpng-2:1.6.34-9.el8_10 | Fixed | RHSA-2026:0241 |
| Red Hat Enterprise Linux 8 | mingw-libpng-0:1.6.34-1.el8_10 | Fixed | RHSA-2026:0125 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | libpng-2:1.6.34-8.el8_2.1 | Fixed | RHSA-2026:0323 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libpng-2:1.6.34-8.el8_4.1 | Fixed | RHSA-2026:0321 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libpng-2:1.6.34-8.el8_4.1 | Fixed | RHSA-2026:0321 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libpng-2:1.6.34-8.el8_6.1 | Fixed | RHSA-2026:0322 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | libpng-2:1.6.34-8.el8_6.1 | Fixed | RHSA-2026:0322 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | libpng-2:1.6.34-8.el8_6.1 | Fixed | RHSA-2026:0322 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | libpng-2:1.6.34-8.el8_8.1 | Fixed | RHSA-2026:0313 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libpng-2:1.6.34-8.el8_8.1 | Fixed | RHSA-2026:0313 |
| Red Hat Enterprise Linux 9 | libpng-2:1.6.37-12.el9_7.1 | Fixed | RHSA-2026:0238 |
| Red Hat Enterprise Linux 9 | libpng-2:1.6.37-12.el9_7.1 | Fixed | RHSA-2026:0238 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | libpng-2:1.6.37-12.el9_0.1 | Fixed | RHSA-2026:0234 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | libpng-2:1.6.37-12.el9_2.1 | Fixed | RHSA-2026:0216 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | libpng-2:1.6.37-12.el9_4.1 | Fixed | RHSA-2026:0211 |
| Red Hat Enterprise Linux 9.6 Extended Update Support | libpng-2:1.6.37-12.el9_6.1 | Fixed | RHSA-2026:0210 |
| Red Hat Hardened Images | libpng-main-1.6.56-1.hum1 | Fixed | RHSA-2026:6732 |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202603041314-0 | Fixed | RHSA-2026:3861 |
| Red Hat OpenShift Container Platform 4.13 | rhcos-413.92.202602240113-0 | Fixed | RHSA-2026:3415 |
| Red Hat OpenShift Container Platform 4.14 | rhcos-414.92.202602171627-0 | Fixed | RHSA-2026:2974 |
| Red Hat OpenShift Container Platform 4.15 | rhcos-415.92.202603101737-0 | Fixed | RHSA-2026:4419 |
| Red Hat OpenShift Container Platform 4.16 | rhcos-416.94.202602101357-0 | Fixed | RHSA-2026:2659 |
| Red Hat OpenShift Container Platform 4.17 | rhcos-417.94.202602090846-0 | Fixed | RHSA-2026:2671 |
| Red Hat OpenShift Container Platform 4.18 | rhcos-418.94.202602022246-0 | Fixed | RHSA-2026:2072 |
| Red Hat OpenShift Container Platform 4.19 | rhcos-4.19.9.6.202602112047-0 | Fixed | RHSA-2026:2633 |
| Red Hat Enterprise Linux 10 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 10 | java-21-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 10 | java-25-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 10 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 6 | libpng | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 7 | java-11-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libpng | Not affected | n/a |
| Red Hat Enterprise Linux 7 | libpng12 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 8 | java-1.8.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 8 | java-17-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 8 | java-21-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libpng12 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | libpng15 | Not affected | n/a |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected | n/a |
| Red Hat Enterprise Linux 9 | firefox | Not affected | n/a |
| Red Hat Enterprise Linux 9 | java-1.8.0-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 9 | java-17-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 9 | java-21-openjdk | Not affected | n/a |
| Red Hat Enterprise Linux 9 | libpng15 | Not affected | n/a |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift/ose-rhel-coreos-8 | Affected | n/a |
| Red Hat build of OpenJDK 1.8 | java-1.8.0-openjdk-portable | Not affected | n/a |
| Red Hat build of OpenJDK 17 | java-17-openjdk-portable | Not affected | n/a |
| Red Hat build of OpenJDK 17 | java-21-openjdk-portable | Not affected | n/a |
| Red Hat build of OpenJDK 21 | java-21-openjdk-portable | Not affected | n/a |
| Red Hat build of OpenJDK 21 | java-21-openjdk-portable-rhel7 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The Red Hat Product Security team has rated this vulnerability as Important as it affects libpng, a widely used library for PNG image processing. The flaw is due to an out-of-bounds read in libpng’s simplified API when handling specially crafted PNG images containing partial transparency and gamma correction data. Successful exploitation could result in information disclosure or cause application crashes in applications processing untrusted PNG content.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (12)
- http://www.openwall.com/lists/oss-security/2025/12/03/6 Mailing List
- http://www.openwall.com/lists/oss-security/2025/12/03/7 Mailing List
- http://www.openwall.com/lists/oss-security/2025/12/03/8 Mailing List
- https://access.redhat.com/security/cve/CVE-2025-66293 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2418711 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201132 Advisory
- https://github.com/pnggroup/libpng/commit/788a624d7387a758ffd5c7ab010f1870dea753a1 x_refsource_MISCPatch
- https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a x_refsource_MISCPatch
- https://github.com/pnggroup/libpng/issues/764 exploitx_refsource_MISCIssue TrackingPatch
- https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f x_refsource_CONFIRMExploitVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-66293
- https://www.cve.org/CVERecord?id=CVE-2025-66293
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/12/03/6 | Mailing List | |
| http://www.openwall.com/lists/oss-security/2025/12/03/7 | Mailing List | |
| http://www.openwall.com/lists/oss-security/2025/12/03/8 | Mailing List | |
| https://access.redhat.com/security/cve/CVE-2025-66293 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2418711 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-201132 | Advisory | |
| https://github.com/pnggroup/libpng/commit/788a624d7387a758ffd5c7ab010f1870dea753a1 | x_refsource_MISCPatch | |
| https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a | x_refsource_MISCPatch | |
| https://github.com/pnggroup/libpng/issues/764 | exploitx_refsource_MISCIssue TrackingPatch | |
| https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f | x_refsource_CONFIRMExploitVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-66293 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-66293 |
Change history (0)
No recorded changes yet.