Affected packages

Android
platform/external/libpng

Package

Name
platform/external/libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
17-next:0
Fixed
17-next:2026-06-01

Affected versions

Other
17-next

Ecosystem specific

{
    "types": [
        "DoS"
    ],
    "spl": "2026-06-01",
    "vanir_signatures": [
        {
            "signature_type": "Line",
            "target": {
                "file": "pngrtran.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "142431579815917050595149758627774442667",
                    "272927091662317434073873080541305664279",
                    "157953137660432174001828262208777562113",
                    "18859720128096665142377665121016717293",
                    "29758299949311403395032393623239671014",
                    "133716557752893825469146816249144492822",
                    "220439571251273879183467563893546976923",
                    "196137712684618856097299568272331956249",
                    "93033579473468926065857562328759513993",
                    "269825164810892428620204552596166445910",
                    "192589771842582979423563747930842796811",
                    "302955417109145449380889295181702462007",
                    "148327097859050943385246922968853226722",
                    "66893984477649212670748750624016804867",
                    "88218227943961402254595364231857576981",
                    "235207835578898950918073996419877268944",
                    "91701423474206393703148646845342482359",
                    "33661941863956276463365653464618370601",
                    "105198871563493525981928965360245956793",
                    "83821909153648921040898813171545953397",
                    "215537866248005020433278903298706335729",
                    "127519463818568031856511559343373374123",
                    "280563186488781227873654848565518679084",
                    "170847585578325137424503411384463820603",
                    "44939304184715697837809482506333420106",
                    "201712516360145619723189840373429469300",
                    "213446584766895851884395923807452635586",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "267951804637912388156798750451886909211",
                    "34257508990693805996541784513832249192",
                    "31394680626899084398855128341867939723",
                    "316661845217483376867579823069220349489",
                    "114348976570001273648347839727977871031",
                    "36327390391482342499393622701650133469",
                    "65229639486500405386046566916682000481",
                    "174698526776586671864747866810143403381",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "28156252738615160062984826911532294902",
                    "199030515033396741143477319374265686834",
                    "39463825579619097639387521443256771792",
                    "294080246133369445051926655700464744279",
                    "163861625584304872204067613632123349874",
                    "18840943533629046803299840017844878599",
                    "99724983862821589799620210607138099819",
                    "275746500009065547276927482712967648166",
                    "205140414084633267087253179517159140377",
                    "14183050999346031323476454689035513494",
                    "24988906718833018275303421651815005056",
                    "115326613720380066375108143996825503088"
                ],
                "threshold": 0.9
            },
            "id": "ASB-A-463995203-029c4011",
            "source": "https://android.googlesource.com/platform/external/libpng/+/b15b668ca6f8fb4407443647e87a15243e0ca1d1",
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngrtran.c",
                "function": "png_set_quantize"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "309960346519937850027350074269399797604",
                "length": 6385.0
            },
            "id": "ASB-A-463995203-16b64e59",
            "source": "https://android.googlesource.com/platform/external/libpng/+/b15b668ca6f8fb4407443647e87a15243e0ca1d1",
            "signature_version": "v1"
        },
        {
            "id": "ASB-A-463995203-2a0f9fc9",
            "target": {
                "file": "pngwrite.c",
                "function": "png_image_write_main"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "287482560906552393873723524112952439303",
                "length": 4091.0
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/external/libpng/+/ac4dc0df9fa3e05500897b0d54e919f205b7f00e",
            "signature_version": "v1"
        },
        {
            "id": "ASB-A-463995203-a17b6a92",
            "target": {
                "file": "pngwrite.c"
            },
            "deprecated": false,
            "signature_type": "Line",
            "digest": {
                "line_hashes": [
                    "275045913931547721476341089800703559241",
                    "57554663865845067308084737628464609765",
                    "212985072000760523111093531678898379495",
                    "81688707855809561231911606613238509787",
                    "57631009309811357417734919908001123984"
                ],
                "threshold": 0.9
            },
            "source": "https://android.googlesource.com/platform/external/libpng/+/ac4dc0df9fa3e05500897b0d54e919f205b7f00e",
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "pngread.c"
            },
            "deprecated": false,
            "match_only_versions": [
                "17-next"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/ba2b00682f311f8059f8eb5f6b6340acfa104abe",
            "signature_version": "v1",
            "id": "ASB-A-463995203-c02b1e1d",
            "digest": {
                "line_hashes": [
                    "301538088964340392606706499638159721560",
                    "219698033185987930519472075599950372348",
                    "118861229656205118168890257752076913306"
                ],
                "threshold": 0.9
            }
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngread.c",
                "function": "png_image_finish_read"
            },
            "deprecated": false,
            "match_only_versions": [
                "17-next"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/ba2b00682f311f8059f8eb5f6b6340acfa104abe",
            "signature_version": "v1",
            "id": "ASB-A-463995203-f4630769",
            "digest": {
                "function_hash": "20229053456542728879289813519749771341",
                "length": 1600.0
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/libpng/+/01a2f4aa4db7b60bdffd03ca80142fe895c8f49c",
        "https://android.googlesource.com/platform/external/libpng/+/ba2b00682f311f8059f8eb5f6b6340acfa104abe",
        "https://android.googlesource.com/platform/external/libpng/+/1dc4632bb6bfbe0def2233d39128518c6afd656f",
        "https://android.googlesource.com/platform/external/libpng/+/b2d61aca8908523a25faaf5041600ace7ee59ab6",
        "https://android.googlesource.com/platform/external/libpng/+/b15b668ca6f8fb4407443647e87a15243e0ca1d1",
        "https://android.googlesource.com/platform/external/libpng/+/ac4dc0df9fa3e05500897b0d54e919f205b7f00e"
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-463995203.json"
platform/external/libpng

Package

Name
platform/external/libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
15:0
Fixed
15:2026-06-01

Affected versions

Other
15

Ecosystem specific

{
    "types": [
        "DoS"
    ],
    "spl": "2026-06-01",
    "vanir_signatures": [
        {
            "id": "ASB-A-463995203-00cae4cc",
            "target": {
                "file": "pngwrite.c"
            },
            "deprecated": false,
            "signature_type": "Line",
            "digest": {
                "line_hashes": [
                    "275045913931547721476341089800703559241",
                    "57554663865845067308084737628464609765",
                    "212985072000760523111093531678898379495",
                    "81688707855809561231911606613238509787",
                    "57631009309811357417734919908001123984"
                ],
                "threshold": 0.9
            },
            "source": "https://android.googlesource.com/platform/external/libpng/+/485f986edf7cc4abbaa485086ec16e797bf24bca",
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngwrite.c",
                "function": "png_image_write_main"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "287482560906552393873723524112952439303",
                "length": 4091.0
            },
            "id": "ASB-A-463995203-2aa7529d",
            "source": "https://android.googlesource.com/platform/external/libpng/+/485f986edf7cc4abbaa485086ec16e797bf24bca",
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngread.c",
                "function": "png_image_finish_read"
            },
            "deprecated": false,
            "match_only_versions": [
                "15"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/dbb29527e0a620619ad8b9133d80e969424ebfb6",
            "signature_version": "v1",
            "id": "ASB-A-463995203-306d0838",
            "digest": {
                "function_hash": "152089211188261457050061368992955969886",
                "length": 2018.0
            }
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngrtran.c",
                "function": "png_init_read_transformations"
            },
            "deprecated": false,
            "match_only_versions": [
                "15"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/2d53ce5f588614c6ebeb35d71c255219330ab9e0",
            "signature_version": "v1",
            "id": "ASB-A-463995203-325fd136",
            "digest": {
                "function_hash": "119953876001774436253963806632048335992",
                "length": 11860.0
            }
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngread.c",
                "function": "png_image_read_direct"
            },
            "deprecated": false,
            "match_only_versions": [
                "15"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/dbb29527e0a620619ad8b9133d80e969424ebfb6",
            "signature_version": "v1",
            "id": "ASB-A-463995203-4d6037e8",
            "digest": {
                "function_hash": "331478663614912565978593027269645593836",
                "length": 5439.0
            }
        },
        {
            "id": "ASB-A-463995203-4ff26ef5",
            "target": {
                "file": "pngrtran.c",
                "function": "png_set_quantize"
            },
            "deprecated": false,
            "signature_type": "Function",
            "digest": {
                "function_hash": "309960346519937850027350074269399797604",
                "length": 6385.0
            },
            "source": "https://android.googlesource.com/platform/external/libpng/+/9f83a580a609c51c9620503b98af8c0933307fb2",
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngrtran.c",
                "function": "png_set_quantize"
            },
            "deprecated": false,
            "match_only_versions": [
                "15"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/31ed93cef63972fc5c656c96d7912cbac55aa4da",
            "signature_version": "v1",
            "id": "ASB-A-463995203-7c0c1208",
            "digest": {
                "function_hash": "282799652390732722450749695380593523084",
                "length": 6147.0
            }
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "pngrtran.c"
            },
            "deprecated": false,
            "match_only_versions": [
                "15"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/2d53ce5f588614c6ebeb35d71c255219330ab9e0",
            "signature_version": "v1",
            "id": "ASB-A-463995203-8e5de9c9",
            "digest": {
                "line_hashes": [
                    "33782656394079741713936793053530985262",
                    "117942120988824518745575478339954718732",
                    "37013518972150728426114520481099257510",
                    "113129152649379904469244060403197744722",
                    "148504440382215712628136361390473060849",
                    "6252962895702760104167041345661964672",
                    "189852415780201247028806368876538901045",
                    "155769962028449576172501037458642109605",
                    "127337745988919388957639519713205807898",
                    "293959720613656618428719165665225121884",
                    "311514019206986862493729774425956471724",
                    "330503303242598610607007919312418616620",
                    "49073011711973440889858581837157180648"
                ],
                "threshold": 0.9
            }
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "pngrtran.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "142431579815917050595149758627774442667",
                    "272927091662317434073873080541305664279",
                    "157953137660432174001828262208777562113",
                    "18859720128096665142377665121016717293",
                    "29758299949311403395032393623239671014",
                    "133716557752893825469146816249144492822",
                    "220439571251273879183467563893546976923",
                    "196137712684618856097299568272331956249",
                    "93033579473468926065857562328759513993",
                    "269825164810892428620204552596166445910",
                    "192589771842582979423563747930842796811",
                    "302955417109145449380889295181702462007",
                    "148327097859050943385246922968853226722",
                    "66893984477649212670748750624016804867",
                    "88218227943961402254595364231857576981",
                    "235207835578898950918073996419877268944",
                    "91701423474206393703148646845342482359",
                    "33661941863956276463365653464618370601",
                    "105198871563493525981928965360245956793",
                    "83821909153648921040898813171545953397",
                    "215537866248005020433278903298706335729",
                    "127519463818568031856511559343373374123",
                    "280563186488781227873654848565518679084",
                    "170847585578325137424503411384463820603",
                    "44939304184715697837809482506333420106",
                    "201712516360145619723189840373429469300",
                    "213446584766895851884395923807452635586",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "267951804637912388156798750451886909211",
                    "34257508990693805996541784513832249192",
                    "31394680626899084398855128341867939723",
                    "316661845217483376867579823069220349489",
                    "114348976570001273648347839727977871031",
                    "36327390391482342499393622701650133469",
                    "65229639486500405386046566916682000481",
                    "174698526776586671864747866810143403381",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "28156252738615160062984826911532294902",
                    "199030515033396741143477319374265686834",
                    "39463825579619097639387521443256771792",
                    "294080246133369445051926655700464744279",
                    "163861625584304872204067613632123349874",
                    "18840943533629046803299840017844878599",
                    "99724983862821589799620210607138099819",
                    "275746500009065547276927482712967648166",
                    "205140414084633267087253179517159140377",
                    "14183050999346031323476454689035513494",
                    "24988906718833018275303421651815005056",
                    "115326613720380066375108143996825503088"
                ],
                "threshold": 0.9
            },
            "id": "ASB-A-463995203-9e8c7634",
            "source": "https://android.googlesource.com/platform/external/libpng/+/9f83a580a609c51c9620503b98af8c0933307fb2",
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "pngrtran.c"
            },
            "deprecated": false,
            "match_only_versions": [
                "15"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/31ed93cef63972fc5c656c96d7912cbac55aa4da",
            "signature_version": "v1",
            "id": "ASB-A-463995203-c148b80a",
            "digest": {
                "line_hashes": [
                    "310430768601001916100977306469197890855",
                    "131058169673690107401609625493491871538",
                    "120927534206599550423552132131692841909",
                    "39288152629051006683908432084350017728",
                    "205735928495447827427748798317942579262",
                    "52765581048667246168412988515153451241",
                    "63281823169701133040883966044472731172"
                ],
                "threshold": 0.9
            }
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "pngread.c"
            },
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/external/libpng/+/dbb29527e0a620619ad8b9133d80e969424ebfb6",
            "match_only_versions": [
                "15"
            ],
            "signature_version": "v1",
            "id": "ASB-A-463995203-d5f2a5d6",
            "digest": {
                "line_hashes": [
                    "256497911793156591007313981010137330804",
                    "109584513501258957054077128149474560042",
                    "192237975258510526477257404003263997624",
                    "30606990160421519100275116613142310139",
                    "312156519594095370516028297434459873770",
                    "220900142416162017220967854775361553404",
                    "36118662072103505342061490674230260058",
                    "168790125413818935852173291986961269893",
                    "120761265379115761546610377133230135172",
                    "189089162184373099497428494853543124429",
                    "106750596262754699567758987243416013094",
                    "226689034820418758914997172041229489211",
                    "97224864048706724588862181400610346559",
                    "266456732266638609151505188293053155290",
                    "203027305669929221271641817633434951738",
                    "242739659333768501417776094650324945646",
                    "2565877639064083502211329144054449282",
                    "334449031200425985162851821346368123662",
                    "330775475673055302350346660593795397359",
                    "176240222955364160527702469812611380358",
                    "11943884251452331759710291842286533529",
                    "213920974765294708682054244944584079400",
                    "282420276832768553133997784203669148659",
                    "328082467098480595943018613690952846180",
                    "85407131502103425500873655207900827151",
                    "327491415051830615961273482749990703128",
                    "215823029670091642558595124854797180422",
                    "1689536822304807430628861611239673510",
                    "76383076396192905111578340454310377134",
                    "262631843307366329793905998192121463093"
                ],
                "threshold": 0.9
            }
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/libpng/+/9f83a580a609c51c9620503b98af8c0933307fb2",
        "https://android.googlesource.com/platform/external/libpng/+/31ed93cef63972fc5c656c96d7912cbac55aa4da",
        "https://android.googlesource.com/platform/external/libpng/+/2d53ce5f588614c6ebeb35d71c255219330ab9e0",
        "https://android.googlesource.com/platform/external/libpng/+/941175abd35156755bba7074c801691dccc45770",
        "https://android.googlesource.com/platform/external/libpng/+/dbb29527e0a620619ad8b9133d80e969424ebfb6",
        "https://android.googlesource.com/platform/external/libpng/+/485f986edf7cc4abbaa485086ec16e797bf24bca"
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-463995203.json"
platform/external/libpng

Package

Name
platform/external/libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16:0
Fixed
16:2026-06-01

Affected versions

Other
16

Ecosystem specific

{
    "types": [
        "DoS"
    ],
    "spl": "2026-06-01",
    "vanir_signatures": [
        {
            "id": "ASB-A-463995203-071f0d0e",
            "target": {
                "file": "pngwrite.c",
                "function": "png_image_write_main"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "287482560906552393873723524112952439303",
                "length": 4091.0
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/external/libpng/+/9d5371ffb374f7ccb095288970e1f0bec6c7e8d0",
            "signature_version": "v1"
        },
        {
            "id": "ASB-A-463995203-409ca73a",
            "target": {
                "file": "pngrtran.c"
            },
            "digest": {
                "line_hashes": [
                    "142431579815917050595149758627774442667",
                    "272927091662317434073873080541305664279",
                    "157953137660432174001828262208777562113",
                    "18859720128096665142377665121016717293",
                    "29758299949311403395032393623239671014",
                    "133716557752893825469146816249144492822",
                    "220439571251273879183467563893546976923",
                    "196137712684618856097299568272331956249",
                    "93033579473468926065857562328759513993",
                    "269825164810892428620204552596166445910",
                    "192589771842582979423563747930842796811",
                    "302955417109145449380889295181702462007",
                    "148327097859050943385246922968853226722",
                    "66893984477649212670748750624016804867",
                    "88218227943961402254595364231857576981",
                    "235207835578898950918073996419877268944",
                    "91701423474206393703148646845342482359",
                    "33661941863956276463365653464618370601",
                    "105198871563493525981928965360245956793",
                    "83821909153648921040898813171545953397",
                    "215537866248005020433278903298706335729",
                    "127519463818568031856511559343373374123",
                    "280563186488781227873654848565518679084",
                    "170847585578325137424503411384463820603",
                    "44939304184715697837809482506333420106",
                    "201712516360145619723189840373429469300",
                    "213446584766895851884395923807452635586",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "267951804637912388156798750451886909211",
                    "34257508990693805996541784513832249192",
                    "31394680626899084398855128341867939723",
                    "316661845217483376867579823069220349489",
                    "114348976570001273648347839727977871031",
                    "36327390391482342499393622701650133469",
                    "65229639486500405386046566916682000481",
                    "174698526776586671864747866810143403381",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "28156252738615160062984826911532294902",
                    "199030515033396741143477319374265686834",
                    "39463825579619097639387521443256771792",
                    "294080246133369445051926655700464744279",
                    "163861625584304872204067613632123349874",
                    "18840943533629046803299840017844878599",
                    "99724983862821589799620210607138099819",
                    "275746500009065547276927482712967648166",
                    "205140414084633267087253179517159140377",
                    "14183050999346031323476454689035513494",
                    "24988906718833018275303421651815005056",
                    "115326613720380066375108143996825503088"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/external/libpng/+/46070ef0c31fb10e934f6de5bbfa045d34d5b67b",
            "signature_version": "v1"
        },
        {
            "id": "ASB-A-463995203-7f22b0c6",
            "target": {
                "file": "pngwrite.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "275045913931547721476341089800703559241",
                    "57554663865845067308084737628464609765",
                    "212985072000760523111093531678898379495",
                    "81688707855809561231911606613238509787",
                    "57631009309811357417734919908001123984"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/external/libpng/+/9d5371ffb374f7ccb095288970e1f0bec6c7e8d0",
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "pngread.c"
            },
            "deprecated": false,
            "match_only_versions": [
                "16"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/aeffb2189f605d028b32e530367d2df32a5cf7f1",
            "signature_version": "v1",
            "id": "ASB-A-463995203-ab7d6560",
            "digest": {
                "line_hashes": [
                    "301538088964340392606706499638159721560",
                    "219698033185987930519472075599950372348",
                    "118861229656205118168890257752076913306"
                ],
                "threshold": 0.9
            }
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngread.c",
                "function": "png_image_finish_read"
            },
            "deprecated": false,
            "match_only_versions": [
                "16"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/aeffb2189f605d028b32e530367d2df32a5cf7f1",
            "signature_version": "v1",
            "id": "ASB-A-463995203-bc814a0f",
            "digest": {
                "function_hash": "20229053456542728879289813519749771341",
                "length": 1600.0
            }
        },
        {
            "id": "ASB-A-463995203-f4416089",
            "target": {
                "file": "pngrtran.c",
                "function": "png_set_quantize"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "309960346519937850027350074269399797604",
                "length": 6385.0
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/external/libpng/+/46070ef0c31fb10e934f6de5bbfa045d34d5b67b",
            "signature_version": "v1"
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/libpng/+/6e48563b0875f557563f703461f25b79876f6017",
        "https://android.googlesource.com/platform/external/libpng/+/aeffb2189f605d028b32e530367d2df32a5cf7f1",
        "https://android.googlesource.com/platform/external/libpng/+/7aad9e82d08b0f17de64ed2de1b7ca39972ee623",
        "https://android.googlesource.com/platform/external/libpng/+/1a04328de58bd491b7f81b9de94247f5b16ba706",
        "https://android.googlesource.com/platform/external/libpng/+/46070ef0c31fb10e934f6de5bbfa045d34d5b67b",
        "https://android.googlesource.com/platform/external/libpng/+/9d5371ffb374f7ccb095288970e1f0bec6c7e8d0"
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-463995203.json"
platform/external/libpng

Package

Name
platform/external/libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
16-qpr2:0
Fixed
16-qpr2:2026-06-01

Affected versions

Other
16-qpr2

Ecosystem specific

{
    "types": [
        "DoS"
    ],
    "spl": "2026-06-01",
    "vanir_signatures": [
        {
            "id": "ASB-A-463995203-0054d6a3",
            "target": {
                "file": "pngrtran.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "142431579815917050595149758627774442667",
                    "272927091662317434073873080541305664279",
                    "157953137660432174001828262208777562113",
                    "18859720128096665142377665121016717293",
                    "29758299949311403395032393623239671014",
                    "133716557752893825469146816249144492822",
                    "220439571251273879183467563893546976923",
                    "196137712684618856097299568272331956249",
                    "93033579473468926065857562328759513993",
                    "269825164810892428620204552596166445910",
                    "192589771842582979423563747930842796811",
                    "302955417109145449380889295181702462007",
                    "148327097859050943385246922968853226722",
                    "66893984477649212670748750624016804867",
                    "88218227943961402254595364231857576981",
                    "235207835578898950918073996419877268944",
                    "91701423474206393703148646845342482359",
                    "33661941863956276463365653464618370601",
                    "105198871563493525981928965360245956793",
                    "83821909153648921040898813171545953397",
                    "215537866248005020433278903298706335729",
                    "127519463818568031856511559343373374123",
                    "280563186488781227873654848565518679084",
                    "170847585578325137424503411384463820603",
                    "44939304184715697837809482506333420106",
                    "201712516360145619723189840373429469300",
                    "213446584766895851884395923807452635586",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "267951804637912388156798750451886909211",
                    "34257508990693805996541784513832249192",
                    "31394680626899084398855128341867939723",
                    "316661845217483376867579823069220349489",
                    "114348976570001273648347839727977871031",
                    "36327390391482342499393622701650133469",
                    "65229639486500405386046566916682000481",
                    "174698526776586671864747866810143403381",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "28156252738615160062984826911532294902",
                    "199030515033396741143477319374265686834",
                    "39463825579619097639387521443256771792",
                    "294080246133369445051926655700464744279",
                    "163861625584304872204067613632123349874",
                    "18840943533629046803299840017844878599",
                    "99724983862821589799620210607138099819",
                    "275746500009065547276927482712967648166",
                    "205140414084633267087253179517159140377",
                    "14183050999346031323476454689035513494",
                    "24988906718833018275303421651815005056",
                    "115326613720380066375108143996825503088"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/external/libpng/+/b15b668ca6f8fb4407443647e87a15243e0ca1d1",
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngread.c",
                "function": "png_image_finish_read"
            },
            "deprecated": false,
            "match_only_versions": [
                "16-qpr2"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/ba2b00682f311f8059f8eb5f6b6340acfa104abe",
            "signature_version": "v1",
            "id": "ASB-A-463995203-4ec44566",
            "digest": {
                "function_hash": "20229053456542728879289813519749771341",
                "length": 1600.0
            }
        },
        {
            "id": "ASB-A-463995203-96fc9479",
            "target": {
                "file": "pngwrite.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "275045913931547721476341089800703559241",
                    "57554663865845067308084737628464609765",
                    "212985072000760523111093531678898379495",
                    "81688707855809561231911606613238509787",
                    "57631009309811357417734919908001123984"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/external/libpng/+/ac4dc0df9fa3e05500897b0d54e919f205b7f00e",
            "signature_version": "v1"
        },
        {
            "signature_type": "Line",
            "target": {
                "file": "pngread.c"
            },
            "deprecated": false,
            "match_only_versions": [
                "16-qpr2"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/ba2b00682f311f8059f8eb5f6b6340acfa104abe",
            "signature_version": "v1",
            "id": "ASB-A-463995203-b37c7fe4",
            "digest": {
                "line_hashes": [
                    "301538088964340392606706499638159721560",
                    "219698033185987930519472075599950372348",
                    "118861229656205118168890257752076913306"
                ],
                "threshold": 0.9
            }
        },
        {
            "id": "ASB-A-463995203-b8645c41",
            "target": {
                "file": "pngrtran.c",
                "function": "png_set_quantize"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "309960346519937850027350074269399797604",
                "length": 6385.0
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/external/libpng/+/b15b668ca6f8fb4407443647e87a15243e0ca1d1",
            "signature_version": "v1"
        },
        {
            "id": "ASB-A-463995203-d845a651",
            "target": {
                "file": "pngwrite.c",
                "function": "png_image_write_main"
            },
            "digest": {
                "function_hash": "287482560906552393873723524112952439303",
                "length": 4091.0
            },
            "signature_type": "Function",
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/external/libpng/+/ac4dc0df9fa3e05500897b0d54e919f205b7f00e",
            "signature_version": "v1"
        }
    ],
    "severity": "Critical",
    "fixes": [
        "https://android.googlesource.com/platform/external/libpng/+/01a2f4aa4db7b60bdffd03ca80142fe895c8f49c",
        "https://android.googlesource.com/platform/external/libpng/+/ba2b00682f311f8059f8eb5f6b6340acfa104abe",
        "https://android.googlesource.com/platform/external/libpng/+/1dc4632bb6bfbe0def2233d39128518c6afd656f",
        "https://android.googlesource.com/platform/external/libpng/+/b2d61aca8908523a25faaf5041600ace7ee59ab6",
        "https://android.googlesource.com/platform/external/libpng/+/b15b668ca6f8fb4407443647e87a15243e0ca1d1",
        "https://android.googlesource.com/platform/external/libpng/+/ac4dc0df9fa3e05500897b0d54e919f205b7f00e"
    ]
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-463995203.json"
platform/external/libpng

Package

Name
platform/external/libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
14:0
Fixed
14:2026-06-01

Affected versions

Other
14

Ecosystem specific

{
    "types": [
        "DoS"
    ],
    "spl": "2026-06-01",
    "vanir_signatures": [
        {
            "signature_type": "Line",
            "target": {
                "file": "pngread.c"
            },
            "deprecated": false,
            "match_only_versions": [
                "14"
            ],
            "source": "https://android.googlesource.com/platform/external/libpng/+/9ee3aafb0dcd9b2103ce1e61092a6f5a1a0a04dc",
            "signature_version": "v1",
            "id": "ASB-A-463995203-70bfe665",
            "digest": {
                "line_hashes": [
                    "301538088964340392606706499638159721560",
                    "219698033185987930519472075599950372348",
                    "118861229656205118168890257752076913306"
                ],
                "threshold": 0.9
            }
        },
        {
            "id": "ASB-A-463995203-7f3f0b45",
            "target": {
                "file": "pngrtran.c"
            },
            "deprecated": false,
            "signature_type": "Line",
            "digest": {
                "line_hashes": [
                    "142431579815917050595149758627774442667",
                    "15337444592123275802624383045953598721",
                    "189011099965420211737479302086092097934",
                    "18859720128096665142377665121016717293",
                    "29758299949311403395032393623239671014",
                    "282456340619610348279468507626170140556",
                    "130649044936064514655708566850117236685",
                    "295597390393899211991832589239338657326",
                    "145471869788955291467609986588294933969",
                    "269825164810892428620204552596166445910",
                    "192589771842582979423563747930842796811",
                    "302955417109145449380889295181702462007",
                    "148327097859050943385246922968853226722",
                    "66893984477649212670748750624016804867",
                    "88218227943961402254595364231857576981",
                    "235207835578898950918073996419877268944",
                    "91701423474206393703148646845342482359",
                    "33661941863956276463365653464618370601",
                    "105198871563493525981928965360245956793",
                    "83821909153648921040898813171545953397",
                    "215537866248005020433278903298706335729",
                    "127519463818568031856511559343373374123",
                    "280563186488781227873654848565518679084",
                    "170847585578325137424503411384463820603",
                    "44939304184715697837809482506333420106",
                    "201712516360145619723189840373429469300",
                    "213446584766895851884395923807452635586",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "267951804637912388156798750451886909211",
                    "34257508990693805996541784513832249192",
                    "31394680626899084398855128341867939723",
                    "316661845217483376867579823069220349489",
                    "114348976570001273648347839727977871031",
                    "36327390391482342499393622701650133469",
                    "65229639486500405386046566916682000481",
                    "174698526776586671864747866810143403381",
                    "122975993703501351249360312875941072659",
                    "106076287252924718314123901295827718832",
                    "248623225569528665484946724597390023522",
                    "28156252738615160062984826911532294902",
                    "199030515033396741143477319374265686834",
                    "39463825579619097639387521443256771792",
                    "294080246133369445051926655700464744279",
                    "163861625584304872204067613632123349874",
                    "18840943533629046803299840017844878599",
                    "99724983862821589799620210607138099819",
                    "275746500009065547276927482712967648166",
                    "205140414084633267087253179517159140377",
                    "14183050999346031323476454689035513494",
                    "24988906718833018275303421651815005056",
                    "115326613720380066375108143996825503088"
                ],
                "threshold": 0.9
            },
            "source": "https://android.googlesource.com/platform/external/libpng/+/8a47b61cf16bde1ee1ea42065db2a1713f6fb40a",
            "signature_version": "v1"
        },
        {
            "signature_type": "Function",
            "target": {
                "file": "pngread.c",
                "function": "png_image_finish_read"
            },
            "deprecated": false,
            "source": "https://android.googlesource.com/platform/external/libpng/+/9ee3aafb0dcd9b2103ce1e61092a6f5a1a0a04dc",
            "match_only_versions": [
                "14"
            ],
            "signature_version": "v1",
            "id": "ASB-A-463995203-92f7c353",
            "digest": {
                "function_hash": "20229053456542728879289813519749771341",
                "length": 1600.0
            }
        },
        {
            "id": "ASB-A-463995203-975634ce",
            "target": {
                "file": "pngrtran.c",
                "function": "png_set_quantize"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "145935780225020635675261560301244134723",
                "length": 6606.0
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/external/libpng/+/8a47b61cf16bde1ee1ea42065db2a1713f6fb40a",
            "signature_version": "v1"
        },
        {
            "id": "ASB-A-463995203-c5174e35",
            "target": {
                "file": "pngwrite.c"
            },
            "deprecated": false,
            "digest": {
                "line_hashes": [
                    "275045913931547721476341089800703559241",
                    "57554663865845067308084737628464609765",
                    "212985072000760523111093531678898379495",
                    "81688707855809561231911606613238509787",
                    "57631009309811357417734919908001123984"
                ],
                "threshold": 0.9
            },
            "signature_type": "Line",
            "source": "https://android.googlesource.com/platform/external/libpng/+/81fa81671b6b6748265807c82912286d1025fc00",
            "signature_version": "v1"
        },
        {
            "id": "ASB-A-463995203-e7c0cbc4",
            "target": {
                "file": "pngwrite.c",
                "function": "png_image_write_main"
            },
            "deprecated": false,
            "digest": {
                "function_hash": "287482560906552393873723524112952439303",
                "length": 4091.0
            },
            "signature_type": "Function",
            "source": "https://android.googlesource.com/platform/external/libpng/+/81fa81671b6b6748265807c82912286d1025fc00",
            "signature_version": "v1"
        }
    ],
    "fixes": [
        "https://android.googlesource.com/platform/external/libpng/+/0e9750be87cbba8e97ee89de420014d40f9bb883",
        "https://android.googlesource.com/platform/external/libpng/+/9ee3aafb0dcd9b2103ce1e61092a6f5a1a0a04dc",
        "https://android.googlesource.com/platform/external/libpng/+/20c02c533b25e9b5327b9bebefdc9e8193ed27de",
        "https://android.googlesource.com/platform/external/libpng/+/dc721fee982cebc9cf07057ff85f2bbb28b65e20",
        "https://android.googlesource.com/platform/external/libpng/+/8a47b61cf16bde1ee1ea42065db2a1713f6fb40a",
        "https://android.googlesource.com/platform/external/libpng/+/81fa81671b6b6748265807c82912286d1025fc00"
    ],
    "severity": "Critical"
}

Database specific

source
"https://storage.googleapis.com/android-osv/ASB-A-463995203.json"