|
|
Log in / Subscribe / Register

Fedora alert FEDORA-2026-a9dc8509e9 (libpng)

From:  updates--- via package-announce <package-announce@lists.fedoraproject.org>
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 42 Update: libpng-1.6.53-1.fc42
Date:  Sat, 10 Jan 2026 01:46:13 +0000
Message-ID:  <20260110014613.F408F82741@bastion01.rdu3.fedoraproject.org>
Archive-link:  Article

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a9dc8509e9 2026-01-10 01:45:09.749962+00:00 -------------------------------------------------------------------------------- Name : libpng Product : Fedora 42 Version : 1.6.53 Release : 1.fc42 URL : http://www.libpng.org/pub/png/ Summary : A library of functions for manipulating PNG image format files Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. -------------------------------------------------------------------------------- Update Information: fixes several security issues -------------------------------------------------------------------------------- ChangeLog: * Mon Dec 8 2025 Michal Hlavinka <mhlavink@redhat.com> - 2:1.6.53-1 - updated to 1.6.53 (#2418775) * Mon Dec 8 2025 Michal Hlavinka <mhlavink@redhat.com> - 2:1.6.52-1 - updated to 1.6.52 (#2418775) * Thu Nov 27 2025 Michal Hlavinka <mhlavink@redhat.com> - 2:1.6.51-1 - updated to 1.6.51 (#2416525) * Thu Jul 24 2025 Fedora Release Engineering <releng@fedoraproject.org> - 2:1.6.50-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Tue Jul 15 2025 Michal Hlavinka <mhlavink@redhat.com> - 2:1.6.50-1 - updated to 1.6.50 * Mon Jun 16 2025 Michal Hlavinka <mhlavink@redhat.com> - 2:1.6.49-1 - updated to 1.6.49 (#2372582) * Mon May 5 2025 Michal Hlavinka <mhlavink@redhat.com> - 2:1.6.48-1 - updated to 1.6.48 (#2363171) * Wed Feb 19 2025 Michal Hlavinka <mhlavink@redhat.com> - 2:1.6.47-1 - updated to 1.6.47 (#2346280) * Fri Jan 31 2025 Michal Hlavinka <mhlavink@redhat.com> - 2:1.6.46-1 - updated to 1.6.46 (#2336284) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2417429 - CVE-2025-64720 libpng: LIBPNG buffer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417429 [ 2 ] Bug #2417448 - CVE-2025-65018 libpng: LIBPNG heap buffer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417448 [ 3 ] Bug #2417459 - CVE-2025-64506 libpng: LIBPNG heap buffer over-read [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2417459 [ 4 ] Bug #2418410 - CVE-2025-64505 libpng: LIBPNG heap buffer overflow via malformed palette index [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418410 [ 5 ] Bug #2418736 - CVE-2025-66293 libpng: LIBPNG out-of-bounds read in png_image_read_composite [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2418736 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a9dc8509e9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds