LIBPNG has a use-after-free in pngsetPLTE, pngsettRNS and pngsethIST leading to corrupted chunk data and potential heap information disclosure. (CVE-2026-34757) Chunk smuggling in push-mode APNG parser via unconsumed chunk body. (CVE-2026-40930)
{ "section": "core" }
"https://advisories.mageia.org/MGASA-2026-0205.json"