Back Linuxsecurity Fedora 42 libpng15 Critical Heap Buffer Overflow Fix CVE-2026
The libpng15 package provides libpng 1.5, an older version of the libpng. library for manipulating PNG (Portable Network Graphics) image format files. This version should be used only if you are unable to use the current version of libpng. Update Information : fix CVE-2026-25646: heap buffer overflow in png_set_quantize
The libpng15 package provides libpng 1.5, an older version of the libpng.
library for manipulating PNG (Portable Network Graphics) image format files.
This version should be used only if you are unable to use the current
fix CVE-2026-25646: heap buffer overflow in png_set_quantize
* Wed Apr 1 2026 Michal Hlavinka - 1.5.30-25 - fix CVE-2026-25646: heap buffer overflow in png_set_quantize (rhbz#2438683) * Fri Jan 16 2026 Fedora Release Engineering - 1.5.30-24 - Rebuilt for * Thu Jul 24 2025 Fedora Release Engineering - 1.5.30-23 - Rebuilt for
* Wed Apr 1 2026 Michal Hlavinka - 1.5.30-25 - fix CVE-2026-25646: heap buffer overflow in png_set_quantize (rhbz#2438683) * Fri Jan 16 2026 Fedora Release Engineering - 1.5.30-24 - Rebuilt for * Thu Jul 24 2025 Fedora Release Engineering - 1.5.30-23 - Rebuilt for
[ 1 ] Bug #2438671 - CVE-2026-25646 libpng15: LIBPNG has a heap buffer overflow in png_set_quantize [fedora-42]
[ 1 ] Bug #2438671 - CVE-2026-25646 libpng15: LIBPNG has a heap buffer overflow in png_set_quantize [fedora-42]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4e514c1c36' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-4e514c1c36' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
