Back Linuxsecurity Debian libjpeg8 Security Flaw Denial of Service Buffer Overflow DSA-6140
For the oldstable distribution (bookworm), this problem has been fixed in version 1.6.39-2+deb12u3. This update also includes two additional security fixes (CVE-2026-22801 and CVE-2026-22695), which had been lined up for the Bookworm point release. For the stable distribution (trixie), this problem has been fixed in version 1.6.48-1+deb13u3. This update also includes two additional security fixes (CVE-2026-22801 and CVE-2026-22695), which had been lined up for the Trixie point release. We recommend that you upgrade your libpng1.6 packages. For the detailed security status of libpng1.6 please refer to its security tracker page at: Further information Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at:
For the oldstable distribution (bookworm), this problem has been fixed in version 1.6.39-2+deb12u3. This update also includes two additional security fixes (CVE-2026-22801 and CVE-2026-22695), which had been lined up for the Bookworm point release. For the stable distribution (trixie), this problem has been fixed in version 1.6.48-1+deb13u3. This update also includes two additional security fixes (CVE-2026-22801 and CVE-2026-22695), which had been lined up for the Trixie point release. We recommend that you upgrade your libpng1.6 packages. For the detailed security status of libpng1.6 please refer to its security tracker page at: Further information Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at:
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
