LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:3405 https://access.redhat.com/errata/RHSA-2026:3405
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:3551 https://access.redhat.com/errata/RHSA-2026:3551
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:3573 https://access.redhat.com/errata/RHSA-2026:3573
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:3577 https://access.redhat.com/errata/RHSA-2026:3577
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:3575 https://access.redhat.com/errata/RHSA-2026:3575
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:3574 https://access.redhat.com/errata/RHSA-2026:3574
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:3576 https://access.redhat.com/errata/RHSA-2026:3576
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4306 https://access.redhat.com/errata/RHSA-2026:4306
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:4731 https://access.redhat.com/errata/RHSA-2026:4731
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:4732 https://access.redhat.com/errata/RHSA-2026:4732
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:4729 https://access.redhat.com/errata/RHSA-2026:4729
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:4730 https://access.redhat.com/errata/RHSA-2026:4730
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:4728 https://access.redhat.com/errata/RHSA-2026:4728