LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, an out-of-bounds read vulnerability exists in png_image_read_composite when processing palette images with PNG_FLAG_OPTIMIZE_ALPHA enabled. The palette compositing code in png_init_read_transformations incorrectly applies background compositing during premultiplication, violating the invariant component ≤ alpha × 257 required by the simplified PNG API. This issue has been patched in version 1.6.51.
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:0125 https://access.redhat.com/errata/RHSA-2026:0125
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:0212 https://access.redhat.com/errata/RHSA-2026:0212
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:0216 https://access.redhat.com/errata/RHSA-2026:0216
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:0211 https://access.redhat.com/errata/RHSA-2026:0211
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:0210 https://access.redhat.com/errata/RHSA-2026:0210
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:0234 https://access.redhat.com/errata/RHSA-2026:0234
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:0237 https://access.redhat.com/errata/RHSA-2026:0237
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:0238 https://access.redhat.com/errata/RHSA-2026:0238
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:0241 https://access.redhat.com/errata/RHSA-2026:0241
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:0251 https://access.redhat.com/errata/RHSA-2026:0251
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:0323 https://access.redhat.com/errata/RHSA-2026:0323
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:0321 https://access.redhat.com/errata/RHSA-2026:0321
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:0313 https://access.redhat.com/errata/RHSA-2026:0313
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:0322 https://access.redhat.com/errata/RHSA-2026:0322