Skip to content
Oracle Linux 8 Vulnerability Advisory for libpng12 and libpng15

Oracle Linux 8 Vulnerability Advisory for libpng12 and libpng15

First seen 18 Jun 2026, 13:42 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 19, 2026 at 13:37 UTC
  • Oracle Linux 8 has issued advisories for vulnerabilities in libpng12 and libpng15.
  • CVE-2026-33416 is a use-after-free vulnerability affecting specific functions.
  • Users are advised to update their systems to prevent potential exploitation.

Oracle has issued advisories for two vulnerabilities in Oracle Linux 8 affecting libpng12 and libpng15. Both advisories address CVE-2026-33416, a use-after-free vulnerability due to pointer aliasing in the png_set_tRNS and png_set_PLTE functions. The affected versions include libpng12-1.2.57-7 and libpng15-1.5.30-9. Users of Oracle Linux 8 are urged to update their systems to mitigate potential exploitation. The vulnerabilities were published on March 26, 2026, and are considered moderate in severity. The patch includes updates for multiple architectures, including i686, x86_64, and aarch64. No active exploitation has been reported at this time, but users should prioritize applying the updates.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 96d ago How this analysis works

Timeline

2026-03-26
CVE-2026-33416 published
A use-after-free vulnerability in libpng12 and libpng15 was disclosed, affecting Oracle Linux 8.
Linuxsecurity
2026-06-18
Oracle releases patches for libpng vulnerabilities
Oracle issued advisories for libpng12 and libpng15, urging users to apply updates to mitigate CVE-2026-33416.
Linuxsecurity

More articles in this cluster (3)

Following this threat?

Track CVE-2026-33416 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed