REDHAT-BUG-2428825: Medium severity libpng LIBPNG vulnerability
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.51 to 1.6.53, there is a heap buffer over-read in the libpng simplified API function pngimagefinishread when processing interlaced 16-bit PNGs with 8-bit output format and non-minimal row stride. This is a regression introduced by the fix for CVE-2025-65018. This vulnerability is fixed in 1.6.54.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
libpngto a version that resolves this vulnerability.Fixed in 1.6.54
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2428825?
The severity of REDHAT-BUG-2428825 is considered high due to the potential for remote code execution resulting from heap buffer over-reads.
How do I fix REDHAT-BUG-2428825?
To fix REDHAT-BUG-2428825, update libpng to version 1.6.54 or later.
Which versions of libpng are affected by REDHAT-BUG-2428825?
Versions of libpng from 1.6.51 to 1.6.53 are affected by REDHAT-BUG-2428825.
What types of images trigger the vulnerability in REDHAT-BUG-2428825?
Interlaced 16-bit PNG images are known to trigger the vulnerability described in REDHAT-BUG-2428825.
Is there a workaround for REDHAT-BUG-2428825 if an update cannot be applied?
There are no known effective workarounds for REDHAT-BUG-2428825, so applying the update is recommended.