LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.51 to 1.6.53, there is a heap buffer over-read in the libpng simplified API function png_image_finish_read when processing interlaced 16-bit PNGs with 8-bit output format and non-minimal row stride. This is a regression introduced by the fix for CVE-2025-65018. This vulnerability is fixed in 1.6.54.
The product reads data past the end, or before the beginning, of the intended buffer.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Libpng | Libpng | 1.6.51 (including) | 1.6.54 (excluding) |
| Red Hat Enterprise Linux 10 | RedHat | libpng-2:1.6.40-8.el10_1.2 | * |
| Red Hat Enterprise Linux 10.0 Extended Update Support | RedHat | libpng-2:1.6.40-8.el10_0.2 | * |
| Red Hat Enterprise Linux 8 | RedHat | mingw-libpng-0:1.6.34-2.el8_10 | * |
| Red Hat Enterprise Linux 9 | RedHat | libpng-2:1.6.37-12.el9_7.2 | * |
| Red Hat Enterprise Linux 9 | RedHat | libpng-2:1.6.37-12.el9_7.2 | * |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | RedHat | libpng-2:1.6.37-12.el9_0.2 | * |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | RedHat | libpng-2:1.6.37-12.el9_2.2 | * |
| Red Hat Enterprise Linux 9.4 Extended Update Support | RedHat | libpng-2:1.6.37-12.el9_4.2 | * |
| Red Hat Enterprise Linux 9.6 Extended Update Support | RedHat | libpng-2:1.6.37-12.el9_6.2 | * |
| Red Hat Discovery 2 | RedHat | discovery/discovery-ui-rhel9:sha256:d167d7926b4a9e7bb51cab5108ad3e826a3ae826536924e8d4129f826c6c5de5 | * |
| Chromium-browser | Ubuntu | upstream | * |
| Libpng1.6 | Ubuntu | devel | * |
| Libpng1.6 | Ubuntu | esm-apps/xenial | * |
| Libpng1.6 | Ubuntu | esm-infra/bionic | * |
| Libpng1.6 | Ubuntu | esm-infra/focal | * |
| Libpng1.6 | Ubuntu | jammy | * |
| Libpng1.6 | Ubuntu | noble | * |
| Libpng1.6 | Ubuntu | plucky | * |
| Libpng1.6 | Ubuntu | questing | * |
| Libpng1.6 | Ubuntu | upstream | * |
| Thunderbird | Ubuntu | plucky | * |