Back Linuxsecurity Mageia 9 libpng Important Use-After-Free and OOB Read MGASA-2026
Description: Use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE. (CVE-2026-33416) Out-of-bounds read/write in the palette expansion on ARM Neon. (CVE-2026-33636)
Description: Use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE. (CVE-2026-33416) Out-of-bounds read/write in the palette expansion on ARM Neon. (CVE-2026-33636)
- - - -
-
-
-
-
MGASA-2026-0070 - Updated libpng packages fix security vulnerabilities
MGASA-2026-0070 - Updated libpng packages fix security vulnerabilities
- 9/core/libpng-1.6.38-1.5.mga9
- 9/core/libpng-1.6.38-1.5.mga9
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
