- What: Security update for libpng1.6
- Impact: Addresses a use-after-free vulnerability in the PNG library
[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6263-1] libpng1.6 security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6263-1] libpng1.6 security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Sun, 10 May 2026 16:11:16 +0000 Message-id: <[🔎] agCuJEGI7mx0oY4G@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6263-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff May 10, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : libpng1.6 CVE ID : CVE-2026-34757 A use-after-free was discovered in libpng, a library implementing an interface for reading and writing PNG (Portable Network Graphics) files. For the oldstable distribution (bookworm), this problem has been fixed in version 1.6.39-2+deb12u5. For the stable distribution (trixie), this problem has been fixed in version 1.6.48-1+deb13u5. We recommend that you upgrade your libpng1.6 packages. For the detailed security status of libpng1.6 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libpng1.6 Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmoArhQACgkQEMKTtsN8 TjYafQ//cEuotT//Mqp0gzt8HJDdWO4UciAQd+xY3re5zgqCYr0EHL51191cIJnp sBqXo7cAi2UQr8vJj/p7MNCgDYzfUV2ocXn7VIXM0zS3hH3xk6VODsOesAeyKWsF 91oSDekvYyRHbB2fTt4GQ5Mo+14URIsn96kEqFil0gHql0m86+5QZkMbKmTytWKP kE/G8n2l8XyLUMsRrlBPQygmOELxUN9hG7AlPBVlzu7dRHaR/uR1oa2vAG71lNFL 6O30xlmAbaR9W+NPPjM+Q8Jra1Pi5pSpxuTgyeSd5FRMDUqA7kOOKutMed/oqvpl 4fNyI7M6ByS1rSeNoG78XGqcGa4UqZxYc3FbKAMAnNF6Oc1eWfJbSXzFNyMpSVSn Furxj9kUO/BK0XM4f+ArfXclgwQFxAvdI7Nvd9PROrgDWVaS2HrT/T7QNF+WvRzX nmGBS4ROR4Y+vIGBc/wBUX37ieBXcPw5Iz0iSaAihTelIGpsWbhmuaxJYSQ/UD+/ YreK0iwkC/BA/E+/PI5IV2H/uBMABJ/vk1/dx2srCYZ9W552UpyoSJ7ep8NXIP1R zY6ttEhoxn2zevDKn8ngk4z4ozQdaqihiaxCGiFob51IdRPIxP9INVu2GI5AK8jk KCkY/ywS11OUQrZZGUNn8SoVVYmobERY4/9gZjFpVFJKcyzUMQU= =ZmaL -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6262-1] lcms2 security update Previous by thread: [SECURITY] [DSA 6262-1] lcms2 security update Index(es): Date Thread