https://seclists.org/oss-sec/2025/q4/233: libpng 1.6.52: Out-of-bounds vulnerability fixed: CVE-2025-66293
Published Dec 3, 2025
·Updated
Affected Software
1 affected component
libpng LIBPNG>=1.6.0<1.6.51
Frequently Asked Questions
1
What is the severity of CVE-2025-66293?
CVE-2025-66293 is classified as high severity with a CVSS score of 7.1.
2
What causes CVE-2025-66293?
CVE-2025-66293 is caused by an out-of-bounds read vulnerability in the simplified API of libpng.
3
How do I fix CVE-2025-66293?
To fix CVE-2025-66293, update to libpng version 1.6.52 or later.
4
Which versions of libpng are affected by CVE-2025-66293?
CVE-2025-66293 affects libpng versions 1.6.0 through 1.6.51.
5
What functions are impacted by CVE-2025-66293?
CVE-2025-66293 impacts the png_image_read_composite function when processing palettes.