Linuxsecurity
Oracle Linux 8 Vulnerability Advisory for libpng12 and libpng15
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Oracle has issued advisories for two vulnerabilities in Oracle Linux 8 affecting libpng12 and libpng15. Both advisories address CVE-2026-33416, a use-after-free vulnerability due to pointer aliasing in the png_set_tRNS and png_set_PLTE functions. The affected versions include libpng12-1.2.57-7 and libpng15-1.5.30-9. Users of Oracle Linux 8 are urged to update their systems to mitigate potential exploitation. The vulnerabilities were published on March 26, 2026, and are considered moderate in severity. The patch includes updates for multiple architectures, including i686, x86_64, and aarch64. No active exploitation has been reported at this time, but users should prioritize applying the updates.
Key Points: • Oracle Linux 8 has issued advisories for vulnerabilities in libpng12 and libpng15. • CVE-2026-33416 is a use-after-free vulnerability affecting specific functions. • Users are advised to update their systems to prevent potential exploitation.