LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:7672 https://access.redhat.com/errata/RHSA-2026:7672
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:7671 https://access.redhat.com/errata/RHSA-2026:7671
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:8052 https://access.redhat.com/errata/RHSA-2026:8052
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:8459 https://access.redhat.com/errata/RHSA-2026:8459
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:9345 https://access.redhat.com/errata/RHSA-2026:9345
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:9638 https://access.redhat.com/errata/RHSA-2026:9638
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:11805 https://access.redhat.com/errata/RHSA-2026:11805
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:11813 https://access.redhat.com/errata/RHSA-2026:11813
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:12264 https://access.redhat.com/errata/RHSA-2026:12264
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:13342 https://access.redhat.com/errata/RHSA-2026:13342
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:13412 https://access.redhat.com/errata/RHSA-2026:13412
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:13533 https://access.redhat.com/errata/RHSA-2026:13533
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:13596 https://access.redhat.com/errata/RHSA-2026:13596
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:13582 https://access.redhat.com/errata/RHSA-2026:13582
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:13583 https://access.redhat.com/errata/RHSA-2026:13583
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:13600 https://access.redhat.com/errata/RHSA-2026:13600
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:13665 https://access.redhat.com/errata/RHSA-2026:13665
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:13682 https://access.redhat.com/errata/RHSA-2026:13682
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:13683 https://access.redhat.com/errata/RHSA-2026:13683
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:13922 https://access.redhat.com/errata/RHSA-2026:13922
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:13977 https://access.redhat.com/errata/RHSA-2026:13977
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:14223 https://access.redhat.com/errata/RHSA-2026:14223
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:14303 https://access.redhat.com/errata/RHSA-2026:14303
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:14790 https://access.redhat.com/errata/RHSA-2026:14790
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:14791 https://access.redhat.com/errata/RHSA-2026:14791
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:15889 https://access.redhat.com/errata/RHSA-2026:15889
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:17524 https://access.redhat.com/errata/RHSA-2026:17524
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:17567 https://access.redhat.com/errata/RHSA-2026:17567
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:17603 https://access.redhat.com/errata/RHSA-2026:17603
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:17642 https://access.redhat.com/errata/RHSA-2026:17642
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:17685 https://access.redhat.com/errata/RHSA-2026:17685