The libpng package contains libraries used by other programs for reading and writing PNG format files. The PNG format was designed as a replacement for GIF and, to a lesser extent, TIFF, with many improvements and extensions and lack of patent problems.
Security Fix(es):
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive(CVE-2025-28162)
Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via pngcreateread_struct() function.(CVE-2025-28164)
{
"severity": "Medium"
}{
"aarch64": [
"libpng-1.6.37-5.oe2003sp4.aarch64.rpm",
"libpng-debuginfo-1.6.37-5.oe2003sp4.aarch64.rpm",
"libpng-debugsource-1.6.37-5.oe2003sp4.aarch64.rpm",
"libpng-devel-1.6.37-5.oe2003sp4.aarch64.rpm",
"libpng-help-1.6.37-5.oe2003sp4.aarch64.rpm"
],
"src": [
"libpng-1.6.37-5.oe2003sp4.src.rpm"
],
"x86_64": [
"libpng-1.6.37-5.oe2003sp4.x86_64.rpm",
"libpng-debuginfo-1.6.37-5.oe2003sp4.x86_64.rpm",
"libpng-debugsource-1.6.37-5.oe2003sp4.x86_64.rpm",
"libpng-devel-1.6.37-5.oe2003sp4.x86_64.rpm",
"libpng-help-1.6.37-5.oe2003sp4.x86_64.rpm"
]
}