CVE-2025-28164: Buffer Overflow
Published Jan 27, 2026
·Updated
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via pngcreatereadstruct() function.
Affected Software
2 affected components
libpng>=1.6.43<1.6.46
libpng LIBPNG>=1.6.43<=1.6.46
Event History
Jan 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-28164?
CVE-2025-28164 has been categorized as a high severity vulnerability due to its potential to cause a denial of service.
2
How do I fix CVE-2025-28164?
To mitigate CVE-2025-28164, update libpng to a version higher than 1.6.46.
3
Who is affected by CVE-2025-28164?
CVE-2025-28164 affects users running libpng versions between 1.6.43 and 1.6.46.
4
What kind of attack does CVE-2025-28164 allow?
CVE-2025-28164 allows a local attacker to exploit the buffer overflow and cause a denial of service.
5
Which function in libpng is related to CVE-2025-28164?
The vulnerability in CVE-2025-28164 is associated with the png_create_read_struct() function in libpng.