https://seclists.org/oss-sec/2025/q4/236: libpng 1.6.52: Out-of-bounds vulnerability fixed: CVE-2025-66293
Published Dec 3, 2025
·Updated
Affected Software
1 affected component
libpng LIBPNG>=1.6.0
Frequently Asked Questions
1
What is the severity of CVE-2025-66293?
CVE-2025-66293 has been classified as a high-severity out-of-bounds vulnerability.
2
How do I fix CVE-2025-66293?
To fix CVE-2025-66293, upgrade to libpng version 1.6.53 or later.
3
What versions of libpng are affected by CVE-2025-66293?
CVE-2025-66293 affects libpng versions prior to 1.6.53.
4
What types of attacks can exploit CVE-2025-66293?
CVE-2025-66293 can be exploited to execute arbitrary code or cause a denial-of-service condition.
5
Is CVE-2025-66293 fixed in the latest libpng release?
Yes, CVE-2025-66293 has been fixed in libpng version 1.6.53.