RHSA-2026:29901: Moderate: libpng security update
Moderate: libpng security update
Other sources
The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.Security Fix(es): libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpngto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_6.3 - Upgrade
Upgrade
redhat/libpng-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_6.3 - Upgrade
Upgrade
redhat/libpng-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_6.3 - Upgrade
Upgrade
redhat/libpng-develto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_6.3 - Upgrade
Upgrade
redhat/libpng-devel-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_6.3 - Upgrade
Upgrade
redhat/libpng-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_6.3 - Compensating control
Refer to the advisory at Red Hat Access article 11258 for the specific update application steps and related mitigations for the libpng use-after-free issue (CVE-2026-33416).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:29901?
The severity of RHSA-2026:29901 is classified as medium with a score of 4.
What vulnerabilities does RHSA-2026:29901 address?
RHSA-2026:29901 addresses vulnerabilities related to libpng that could impact security.
How do I fix RHSA-2026:29901?
To fix RHSA-2026:29901, you should apply the recommended security update for libpng provided by Red Hat.
What systems are affected by RHSA-2026:29901?
RHSA-2026:29901 affects Red Hat Enterprise Linux for x86_64 and Red Hat Enterprise Linux Server - AUS.
When was RHSA-2026:29901 published?
RHSA-2026:29901 was published on June 25, 2026.