ALSA-2026:4306

See a problem?
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:4306.json
JSON Data
https://api.osv.dev/v1/vulns/ALSA-2026:4306
Related
Published
2026-03-11T00:00:00Z
Modified
2026-03-16T08:43:58.160007Z
Summary
Important: mingw-libpng security update
Details

MinGW Windows Libpng library.

Security Fix(es):

  • libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801)
  • libpng: libpng: Denial of service and information disclosure via heap buffer over-read in pngimagefinish_read (CVE-2026-22695)
  • libpng: LIBPNG has a heap buffer overflow in pngsetquantize (CVE-2026-25646)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8 / mingw32-libpng

Package

Name
mingw32-libpng
Purl
pkg:rpm/almalinux/mingw32-libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.34-2.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:4306.json"

AlmaLinux:8 / mingw32-libpng-static

Package

Name
mingw32-libpng-static
Purl
pkg:rpm/almalinux/mingw32-libpng-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.34-2.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:4306.json"

AlmaLinux:8 / mingw64-libpng

Package

Name
mingw64-libpng
Purl
pkg:rpm/almalinux/mingw64-libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.34-2.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:4306.json"

AlmaLinux:8 / mingw64-libpng-static

Package

Name
mingw64-libpng-static
Purl
pkg:rpm/almalinux/mingw64-libpng-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.34-2.el8_10

Database specific

source
"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:4306.json"