Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Two vulnerabilities have been identified in the libpng library affecting Fedora 42. The first, CVE-2026-25646, is a heap buffer overflow in the libpng12 package (version 1.2.57-25) and the second affects the libpng15 package (version 1.5.30-25). Both vulnerabilities allow for potential exploitation...
A critical vulnerability identified as CVE-2026-25646 has been found in libpng, affecting numerous operating systems and web browsers. This flaw, a heap buffer overflow in the png_set_quantize() function, could allow attackers to crash applications or execute arbitrary code. The vulnerability was pu...
The libpng package in Fedora has been updated to address CVE-2026-22695, a medium severity heap buffer over-read vulnerability. This affects users who manipulate PNG image files, necessitating an update to version 1.6.54 released on January 12, 2026.