OESA-2026-2149

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-2149
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-2149.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-2149
Upstream
  • CVE-2026-34757
Published
2026-05-03T09:56:10Z
Modified
2026-05-03T10:18:50.901359Z
Summary
libpng security update
Details

The libpng package contains libraries used by other programs for reading and writing PNG format files. The PNG format was designed as a replacement for GIF and, to a lesser extent, TIFF, with many improvements and extensions and lack of patent problems.

Security Fix(es):

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from pnggetPLTE, pnggettRNS, or pnggethIST back into the corresponding setter on the same pngstruct/pnginfo pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.(CVE-2026-34757)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP4
libpng

Package

Name
libpng
Purl
pkg:rpm/openEuler/libpng&distro=openEuler-20.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.37-8.oe2003sp4

Ecosystem specific

{
    "aarch64": [
        "libpng-1.6.37-8.oe2003sp4.aarch64.rpm",
        "libpng-debuginfo-1.6.37-8.oe2003sp4.aarch64.rpm",
        "libpng-debugsource-1.6.37-8.oe2003sp4.aarch64.rpm",
        "libpng-devel-1.6.37-8.oe2003sp4.aarch64.rpm",
        "libpng-help-1.6.37-8.oe2003sp4.aarch64.rpm"
    ],
    "src": [
        "libpng-1.6.37-8.oe2003sp4.src.rpm"
    ],
    "x86_64": [
        "libpng-1.6.37-8.oe2003sp4.x86_64.rpm",
        "libpng-debuginfo-1.6.37-8.oe2003sp4.x86_64.rpm",
        "libpng-debugsource-1.6.37-8.oe2003sp4.x86_64.rpm",
        "libpng-devel-1.6.37-8.oe2003sp4.x86_64.rpm",
        "libpng-help-1.6.37-8.oe2003sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2149.json"
openEuler:22.03-LTS-SP4
libpng

Package

Name
libpng
Purl
pkg:rpm/openEuler/libpng&distro=openEuler-22.03-LTS-SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.38-9.oe2203sp4

Ecosystem specific

{
    "aarch64": [
        "libpng-1.6.38-9.oe2203sp4.aarch64.rpm",
        "libpng-debuginfo-1.6.38-9.oe2203sp4.aarch64.rpm",
        "libpng-debugsource-1.6.38-9.oe2203sp4.aarch64.rpm",
        "libpng-devel-1.6.38-9.oe2203sp4.aarch64.rpm",
        "libpng-help-1.6.38-9.oe2203sp4.aarch64.rpm",
        "libpng-static-1.6.38-9.oe2203sp4.aarch64.rpm",
        "libpng-tools-1.6.38-9.oe2203sp4.aarch64.rpm"
    ],
    "src": [
        "libpng-1.6.38-9.oe2203sp4.src.rpm"
    ],
    "x86_64": [
        "libpng-1.6.38-9.oe2203sp4.x86_64.rpm",
        "libpng-debuginfo-1.6.38-9.oe2203sp4.x86_64.rpm",
        "libpng-debugsource-1.6.38-9.oe2203sp4.x86_64.rpm",
        "libpng-devel-1.6.38-9.oe2203sp4.x86_64.rpm",
        "libpng-help-1.6.38-9.oe2203sp4.x86_64.rpm",
        "libpng-static-1.6.38-9.oe2203sp4.x86_64.rpm",
        "libpng-tools-1.6.38-9.oe2203sp4.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2149.json"
openEuler:24.03-LTS
libpng

Package

Name
libpng
Purl
pkg:rpm/openEuler/libpng&distro=openEuler-24.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.40-9.oe2403sp3

Ecosystem specific

{
    "noarch": [
        "libpng-help-1.6.40-9.oe2403.noarch.rpm",
        "libpng-help-1.6.40-9.oe2403sp1.noarch.rpm",
        "libpng-help-1.6.40-9.oe2403sp3.noarch.rpm"
    ],
    "aarch64": [
        "libpng-1.6.40-9.oe2403.aarch64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403.aarch64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403.aarch64.rpm",
        "libpng-devel-1.6.40-9.oe2403.aarch64.rpm",
        "libpng-static-1.6.40-9.oe2403.aarch64.rpm",
        "libpng-tools-1.6.40-9.oe2403.aarch64.rpm",
        "libpng-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-devel-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-static-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-tools-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-devel-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-static-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-tools-1.6.40-9.oe2403sp3.aarch64.rpm"
    ],
    "src": [
        "libpng-1.6.40-9.oe2403.src.rpm",
        "libpng-1.6.40-9.oe2403sp1.src.rpm",
        "libpng-1.6.40-9.oe2403sp3.src.rpm"
    ],
    "x86_64": [
        "libpng-1.6.40-9.oe2403.x86_64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403.x86_64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403.x86_64.rpm",
        "libpng-devel-1.6.40-9.oe2403.x86_64.rpm",
        "libpng-static-1.6.40-9.oe2403.x86_64.rpm",
        "libpng-tools-1.6.40-9.oe2403.x86_64.rpm",
        "libpng-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-devel-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-static-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-tools-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-devel-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-static-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-tools-1.6.40-9.oe2403sp3.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2149.json"
openEuler:24.03-LTS-SP1
libpng

Package

Name
libpng
Purl
pkg:rpm/openEuler/libpng&distro=openEuler-24.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.40-9.oe2403sp1

Ecosystem specific

{
    "noarch": [
        "libpng-help-1.6.40-9.oe2403sp1.noarch.rpm"
    ],
    "aarch64": [
        "libpng-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-devel-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-static-1.6.40-9.oe2403sp1.aarch64.rpm",
        "libpng-tools-1.6.40-9.oe2403sp1.aarch64.rpm"
    ],
    "src": [
        "libpng-1.6.40-9.oe2403sp1.src.rpm"
    ],
    "x86_64": [
        "libpng-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-devel-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-static-1.6.40-9.oe2403sp1.x86_64.rpm",
        "libpng-tools-1.6.40-9.oe2403sp1.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2149.json"
openEuler:24.03-LTS-SP3
libpng

Package

Name
libpng
Purl
pkg:rpm/openEuler/libpng&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.40-9.oe2403sp3

Ecosystem specific

{
    "noarch": [
        "libpng-help-1.6.40-9.oe2403sp3.noarch.rpm"
    ],
    "aarch64": [
        "libpng-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-devel-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-static-1.6.40-9.oe2403sp3.aarch64.rpm",
        "libpng-tools-1.6.40-9.oe2403sp3.aarch64.rpm"
    ],
    "src": [
        "libpng-1.6.40-9.oe2403sp3.src.rpm"
    ],
    "x86_64": [
        "libpng-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-debuginfo-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-debugsource-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-devel-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-static-1.6.40-9.oe2403sp3.x86_64.rpm",
        "libpng-tools-1.6.40-9.oe2403sp3.x86_64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-2149.json"