Bug 2428824 (CVE-2026-22801) - CVE-2026-22801 libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
Summary: CVE-2026-22801 libpng: libpng: Information disclosure and denial of service v...
Keywords:
Status: NEW
Alias: CVE-2026-22801
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2437225 2437226 2437227 2437228 2437229 2437230 2437231 2437232 2437233 2437234 2437235 2437236 2437237 2437241 2437242 2437243 2437244 2437245 2437246 2437247 2437252 2437238 2437239 2437240 2437248 2437249 2437250 2437251
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-01-13 00:10 UTC by OSIDB Bzimport
Modified: 2026-03-23 14:31 UTC (History)
18 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2026:3432 0 None None None 2026-02-26 12:21:49 UTC
Red Hat Product Errata RHBA-2026:3433 0 None None None 2026-02-26 12:26:43 UTC
Red Hat Product Errata RHBA-2026:3466 0 None None None 2026-03-02 01:03:11 UTC
Red Hat Product Errata RHBA-2026:3467 0 None None None 2026-03-02 01:03:51 UTC
Red Hat Product Errata RHBA-2026:3650 0 None None None 2026-03-03 13:54:01 UTC
Red Hat Product Errata RHBA-2026:4783 0 None None None 2026-03-17 15:30:52 UTC
Red Hat Product Errata RHBA-2026:4784 0 None None None 2026-03-17 15:22:54 UTC
Red Hat Product Errata RHBA-2026:4941 0 None None None 2026-03-18 18:08:46 UTC
Red Hat Product Errata RHBA-2026:5367 0 None None None 2026-03-23 14:31:09 UTC
Red Hat Product Errata RHBA-2026:5377 0 None None None 2026-03-23 11:31:33 UTC
Red Hat Product Errata RHSA-2026:3405 0 None None None 2026-02-26 07:21:00 UTC
Red Hat Product Errata RHSA-2026:3551 0 None None None 2026-03-02 15:27:04 UTC
Red Hat Product Errata RHSA-2026:3573 0 None None None 2026-03-02 19:53:11 UTC
Red Hat Product Errata RHSA-2026:3574 0 None None None 2026-03-03 00:37:00 UTC
Red Hat Product Errata RHSA-2026:3575 0 None None None 2026-03-03 00:06:26 UTC
Red Hat Product Errata RHSA-2026:3576 0 None None None 2026-03-03 01:00:04 UTC
Red Hat Product Errata RHSA-2026:3577 0 None None None 2026-03-02 19:59:13 UTC
Red Hat Product Errata RHSA-2026:4306 0 None None None 2026-03-11 11:20:25 UTC
Red Hat Product Errata RHSA-2026:4728 0 None None None 2026-03-17 10:13:25 UTC
Red Hat Product Errata RHSA-2026:4729 0 None None None 2026-03-17 09:52:17 UTC
Red Hat Product Errata RHSA-2026:4730 0 None None None 2026-03-17 10:07:53 UTC
Red Hat Product Errata RHSA-2026:4731 0 None None None 2026-03-17 09:34:28 UTC
Red Hat Product Errata RHSA-2026:4732 0 None None None 2026-03-17 09:35:10 UTC

Description OSIDB Bzimport 2026-01-13 00:10:31 UTC
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.

Comment 2 errata-xmlrpc 2026-02-26 07:20:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:3405 https://access.redhat.com/errata/RHSA-2026:3405

Comment 3 errata-xmlrpc 2026-03-02 15:27:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:3551 https://access.redhat.com/errata/RHSA-2026:3551

Comment 4 errata-xmlrpc 2026-03-02 19:53:09 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2026:3573 https://access.redhat.com/errata/RHSA-2026:3573

Comment 5 errata-xmlrpc 2026-03-02 19:59:10 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:3577 https://access.redhat.com/errata/RHSA-2026:3577

Comment 6 errata-xmlrpc 2026-03-03 00:06:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:3575 https://access.redhat.com/errata/RHSA-2026:3575

Comment 7 errata-xmlrpc 2026-03-03 00:36:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2026:3574 https://access.redhat.com/errata/RHSA-2026:3574

Comment 8 errata-xmlrpc 2026-03-03 01:00:02 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:3576 https://access.redhat.com/errata/RHSA-2026:3576

Comment 9 errata-xmlrpc 2026-03-11 11:20:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:4306 https://access.redhat.com/errata/RHSA-2026:4306

Comment 10 errata-xmlrpc 2026-03-17 09:34:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:4731 https://access.redhat.com/errata/RHSA-2026:4731

Comment 11 errata-xmlrpc 2026-03-17 09:35:08 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.2 Advanced Update Support

Via RHSA-2026:4732 https://access.redhat.com/errata/RHSA-2026:4732

Comment 12 errata-xmlrpc 2026-03-17 09:52:15 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:4729 https://access.redhat.com/errata/RHSA-2026:4729

Comment 13 errata-xmlrpc 2026-03-17 10:07:51 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2026:4730 https://access.redhat.com/errata/RHSA-2026:4730

Comment 14 errata-xmlrpc 2026-03-17 10:13:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:4728 https://access.redhat.com/errata/RHSA-2026:4728


Note You need to log in before you can comment on or make changes to this bug.