VDB
ALSA-2026%3A0241
ALSA-2026%3A0241
PUBLISHED
The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files. Security Fix(es): * libpng: LIBPNG buffer overflow (CVE-2025-64720) * libpng: LIBPNG heap buffer overflow (CVE-2025-65018) * libpng: LIBPNG out-of-bounds read in png_image_read_composite (CVE-2025-66293) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| AlmaLinux:8 | libpng | 0, 0 |
| AlmaLinux:8 | libpng-devel | 0, 0 |
Timeline
- Jan 7, 2026 CVE Published
- Jan 7, 2026 CVE Updated
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Distribution Patch
- Mar 6, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2026:0241 vendor-advisory
- https://access.redhat.com/security/cve/CVE-2025-64720 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2025-65018 third-party-advisory
- https://access.redhat.com/security/cve/CVE-2025-66293 third-party-advisory
- https://bugzilla.redhat.com/2416904 third-party-advisory
- https://bugzilla.redhat.com/2416907 third-party-advisory
- https://bugzilla.redhat.com/2418711 third-party-advisory
- https://errata.almalinux.org/8/ALSA-2026-0241.html vendor-advisory