RHSA-2026:29900: Moderate: libpng security update
Moderate: libpng security update
Other sources
The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.Security Fix(es): libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpngto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_8.3 - Upgrade
Upgrade
redhat/libpng-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_8.3 - Upgrade
Upgrade
redhat/libpng-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_8.3 - Upgrade
Upgrade
redhat/libpng-develto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_8.3 - Upgrade
Upgrade
redhat/libpng-devel-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_8.3 - Upgrade
Upgrade
redhat/libpng-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_8.3
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:29900?
The severity of RHSA-2026:29900 is classified as medium, with a score of 4.
What is the vulnerability described in RHSA-2026:29900?
RHSA-2026:29900 describes a use-after-free vulnerability in libpng that can lead to arbitrary code execution.
How do I fix RHSA-2026:29900?
To fix RHSA-2026:29900, you need to update the libpng packages to the latest version provided in the Red Hat errata.
What systems are affected by RHSA-2026:29900?
RHSA-2026:29900 affects various versions of Red Hat Enterprise Linux, including server editions for Power LE and x86_64.
What is the CVE identifier associated with RHSA-2026:29900?
The CVE identifier associated with RHSA-2026:29900 is CVE-2026-33416.