CVE-2025-65018: LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`
Libpng has been updated to version 1.6.51, which contains fixes for security vulnerabilities including CVE-2025-65018 and CVE-2025-64720.
Other sources
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function pngimagefinishread when processing 16-bit interlaced PNGs with 8-bit output format. Attacker-crafted interlaced PNG files cause heap writes beyond allocated buffer bounds. This issue has been patched in version 1.6.51.
— MITRE
LIBPNG is vulnerable to a heap buffer overflow in pngcombinerow triggered via pngimagefinishread
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libpngto a version that resolves this vulnerability.Fixed in 1.6.51Patch CVE-2025-65018 - Upgrade
Upgrade
libpngto a version that resolves this vulnerability.Fixed in 1.6.51Patch CVE-2025-64720 - Upgrade
Upgrade
libpngto a version that resolves this vulnerability.Fixed in 1.6.51Patch CVE-2025-64505 - Upgrade
Upgrade
libpngto a version that resolves this vulnerability.Fixed in 1.6.51Patch CVE-2025-64506
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-65018?
CVE-2025-65018 has been classified as a high severity vulnerability due to the risk of a heap buffer overflow.
How do I fix CVE-2025-65018?
To mitigate CVE-2025-65018, upgrade libpng to version 1.6.51 or later.
What software is affected by CVE-2025-65018?
CVE-2025-65018 affects libpng versions from 1.6.0 to before 1.6.51.
What type of vulnerability is CVE-2025-65018?
CVE-2025-65018 is a heap buffer overflow vulnerability found in the simplified API function of libpng.
When was CVE-2025-65018 disclosed?
CVE-2025-65018 was disclosed with available patches in early 2025.