RHSA-2026:50808: Moderate: libpng security update
Moderate: libpng security update
Other sources
The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.Security Fix(es): libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/libpngto a version that resolves this vulnerability.Fixed in 1.5.13-8.el7_9.3 - Upgrade
Upgrade
redhat/libpng-debuginfoto a version that resolves this vulnerability.Fixed in 1.5.13-8.el7_9.3 - Upgrade
Upgrade
redhat/libpng-develto a version that resolves this vulnerability.Fixed in 1.5.13-8.el7_9.3 - Upgrade
Upgrade
redhat/libpng-staticto a version that resolves this vulnerability.Fixed in 1.5.13-8.el7_9.3 - Compensating control
Apply the Red Hat libpng security update described in the advisory and remediate the use-after-free issue that enables arbitrary code execution (CVE-2026-33416).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:50808?
The severity of RHSA-2026:50808 is classified as medium with a score of 4.
What is the risk associated with RHSA-2026:50808?
The risk associated with RHSA-2026:50808 is rated at 19.
How do I fix RHSA-2026:50808?
To fix RHSA-2026:50808, update the libpng package to the latest version provided by Red Hat.
What vulnerability is addressed in RHSA-2026:50808?
RHSA-2026:50808 addresses a use-after-free vulnerability in libpng that can lead to arbitrary code execution.
Which package versions are affected by RHSA-2026:50808?
RHSA-2026:50808 affects the libpng packages including libpng, libpng-debuginfo, libpng-devel, and libpng-static from Red Hat.