Bug 2445566 (CVE-2026-3713)

Summary: CVE-2026-3713 libpng: libpng: Heap-based buffer overflow in pnm2png allows information disclosure and denial of service
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: adudiak, ahughes, caswilli, crizzo, fferrari, fitzsim, gotiwari, gtanzill, jbuscemi, jgrulich, jhorak, kaycoth, khosford, kshier, mtorre, mvyas, neugens, pjindal, ppisar, stcannon, teagle, tfitzsim, tpopela, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
URL: https://github.com/pnggroup/libpng/issues/794
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in libpng. A local attacker could exploit this vulnerability by manipulating the width/height arguments in the `do_pnm2png` function of the `pnm2png` component. This manipulation causes a heap-based buffer overflow, which could lead to information disclosure and denial of service (DoS).
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2445665, 2445666, 2445667, 2445668, 2445671, 2445672, 2445673, 2445674, 2445675, 2445676, 2445677, 2445678, 2445679, 2445682, 2445669, 2445670, 2445680, 2445681    
Bug Blocks:    

Description OSIDB Bzimport 2026-03-08 07:01:18 UTC
A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.