Back Linuxsecurity Fedora 42: Critical Buffer Overflow and Heap Vulnerabilities in libpng
The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. Update Information : fixes several security issues
The libpng package contains a library of functions for creating and
manipulating PNG (Portable Network Graphics) image format files. PNG
is a bit-mapped graphics format similar to the GIF format. PNG was
created to replace the GIF format, since GIF uses a patented data
compression algorithm.
Libpng should be installed if you need to manipulate PNG format image
fixes several security issues
* Mon Dec 8 2025 Michal Hlavinka - 2:1.6.53-1 - updated to 1.6.53 (#2418775) * Mon Dec 8 2025 Michal Hlavinka - 2:1.6.52-1 - updated to 1.6.52 (#2418775) * Thu Nov 27 2025 Michal Hlavinka - 2:1.6.51-1 - updated to 1.6.51 (#2416525) * Thu Jul 24 2025 Fedora Release Engineering - 2:1.6.50-2 - Rebuilt for * Tue Jul 15 2025 Michal Hlavinka - 2:1.6.50-1 - updated to 1.6.50 * Mon Jun 16 2025 Michal Hlavinka - 2:1.6.49-1 - updated to 1.6.49 (#2372582) * Mon May 5 2025 Michal Hlavinka - 2:1.6.48-1 - updated to 1.6.48 (#2363171) * Wed Feb 19 2025 Michal Hlavinka - 2:1.6.47-1 - updated to 1.6.47 (#2346280) * Fri Jan 31 2025 Michal Hlavinka - 2:1.6.46-1 - updated to 1.6.46 (#2336284)
* Mon Dec 8 2025 Michal Hlavinka - 2:1.6.53-1 - updated to 1.6.53 (#2418775) * Mon Dec 8 2025 Michal Hlavinka - 2:1.6.52-1 - updated to 1.6.52 (#2418775) * Thu Nov 27 2025 Michal Hlavinka - 2:1.6.51-1 - updated to 1.6.51 (#2416525) * Thu Jul 24 2025 Fedora Release Engineering - 2:1.6.50-2 - Rebuilt for * Tue Jul 15 2025 Michal Hlavinka - 2:1.6.50-1 - updated to 1.6.50 * Mon Jun 16 2025 Michal Hlavinka - 2:1.6.49-1 - updated to 1.6.49 (#2372582) * Mon May 5 2025 Michal Hlavinka - 2:1.6.48-1 - updated to 1.6.48 (#2363171) * Wed Feb 19 2025 Michal Hlavinka - 2:1.6.47-1 - updated to 1.6.47 (#2346280) * Fri Jan 31 2025 Michal Hlavinka - 2:1.6.46-1 - updated to 1.6.46 (#2336284)
[ 1 ] Bug #2417429 - CVE-2025-64720 libpng: LIBPNG buffer overflow [fedora-42] [ 2 ] Bug #2417448 - CVE-2025-65018 libpng: LIBPNG heap buffer overflow [fedora-42] [ 3 ] Bug #2417459 - CVE-2025-64506 libpng: LIBPNG heap buffer over-read [fedora-42] [ 4 ] Bug #2418410 - CVE-2025-64505 libpng: LIBPNG heap buffer overflow via malformed palette index [fedora-42] [ 5 ] Bug #2418736 - CVE-2025-66293 libpng: LIBPNG out-of-bounds read in png_image_read_composite [fedora-42]
[ 1 ] Bug #2417429 - CVE-2025-64720 libpng: LIBPNG buffer overflow [fedora-42] [ 2 ] Bug #2417448 - CVE-2025-65018 libpng: LIBPNG heap buffer overflow [fedora-42] [ 3 ] Bug #2417459 - CVE-2025-64506 libpng: LIBPNG heap buffer over-read [fedora-42] [ 4 ] Bug #2418410 - CVE-2025-64505 libpng: LIBPNG heap buffer overflow via malformed palette index [fedora-42] [ 5 ] Bug #2418736 - CVE-2025-66293 libpng: LIBPNG out-of-bounds read in png_image_read_composite [fedora-42]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a9dc8509e9' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
