RHSA-2026:29902: Moderate: libpng security update
Moderate: libpng security update
Other sources
The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.Security Fix(es): libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpngto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_4.3 - Upgrade
Upgrade
redhat/libpng-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_4.3 - Upgrade
Upgrade
redhat/libpng-debugsourceto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_4.3 - Upgrade
Upgrade
redhat/libpng-develto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_4.3 - Upgrade
Upgrade
redhat/libpng-devel-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_4.3 - Upgrade
Upgrade
redhat/libpng-tools-debuginfoto a version that resolves this vulnerability.Fixed in 1.6.34-8.el8_4.3
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:29902?
The severity of RHSA-2026:29902 is classified as medium.
How do I fix RHSA-2026:29902?
You can fix RHSA-2026:29902 by applying the latest available updates for libpng from Red Hat.
What software is affected by RHSA-2026:29902?
RHSA-2026:29902 affects Red Hat Enterprise Linux Server and the Extended Update Support Extension for x86_64.
What does the libpng security update in RHSA-2026:29902 address?
The libpng security update in RHSA-2026:29902 addresses moderate vulnerabilities in the library that may pose security risks.
When was RHSA-2026:29902 published?
RHSA-2026:29902 was published on June 25, 2026.