Critical libpng Vulnerabilities Affecting Multiple Ubuntu Releases

Critical libpng Vulnerabilities Affecting Multiple Ubuntu Releases

First seen 7 May 2026, 21:08 UTC UbuntuLinuxsecurity 91% similarity 74.0

Article Content

Browse articles
ThreatCluster

On May 7, 2026, Ubuntu published USN-8251-1, addressing several critical vulnerabilities in libpng, affecting Ubuntu 25.10, 24.04 LTS, and 22.04 LTS. The vulnerabilities include improper memory handling when processing specially crafted PNG files, which could lead to denial of service or arbitrary code execution (CVE-2026-33416, CVE-2026-33636). Additionally, a flaw in certain setter APIs could potentially expose sensitive information (CVE-2026-34757). Users and automated systems are at risk if they open malicious PNG files. The vulnerabilities were disclosed on March 26, 2026, and April 9, 2026, respectively. Affected users are advised to update their systems to the latest package versions to mitigate these risks.

Key Points: • Critical vulnerabilities in libpng could lead to denial of service or arbitrary code execution. • Affected Ubuntu versions include 25.10, 24.04 LTS, and 22.04 LTS. • Users are urged to update their systems to the latest libpng package versions immediately.

ThreatCluster AI

Timeline

2026-03-26
CVE-2026-33416 published
libpng vulnerability disclosed, allowing denial of service or arbitrary code execution via crafted PNG files.
Ubuntu
2026-03-26
CVE-2026-33636 published
libpng vulnerability affecting ARM processors disclosed, enabling similar attack vectors.
Ubuntu
2026-04-09
CVE-2026-34757 published
Vulnerability in libpng's setter APIs disclosed, potentially exposing sensitive information.
Ubuntu
2026-05-07
USN-8251-1 published
Ubuntu releases advisory for critical libpng vulnerabilities and recommends updates for affected systems.
Ubuntu

Community

Browse all →