Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
RHSA-2026:0234
See a problem?
Please try reporting it
to the source
first.
Source
https://access.redhat.com/errata/RHSA-2026:0234
Import Source
https://security.access.redhat.com/data/osv/RHSA-2026:0234.json
JSON Data
https://api.osv.dev/v1/vulns/RHSA-2026:0234
Upstream
CVE-2025-64720
CVE-2025-65018
CVE-2025-66293
Published
2026-01-08T10:17:38Z
Modified
2026-01-08T10:45:04.412040Z
Severity
7.1 (High)
CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
CVSS Calculator
Summary
Red Hat Security Advisory: libpng security update
Details
References
https://access.redhat.com/errata/RHSA-2026:0234
https://access.redhat.com/security/updates/classification/#important
https://bugzilla.redhat.com/show_bug.cgi?id=2416904
https://bugzilla.redhat.com/show_bug.cgi?id=2416907
https://bugzilla.redhat.com/show_bug.cgi?id=2418711
https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_0234.json
https://access.redhat.com/security/cve/CVE-2025-64720
https://www.cve.org/CVERecord?id=CVE-2025-64720
https://nvd.nist.gov/vuln/detail/CVE-2025-64720
https://github.com/pnggroup/libpng/commit/08da33b4c88cfcd36e5a706558a8d7e0e4773643
https://github.com/pnggroup/libpng/issues/686
https://github.com/pnggroup/libpng/pull/751
https://github.com/pnggroup/libpng/security/advisories/GHSA-hfc7-ph9c-wcww
https://access.redhat.com/security/cve/CVE-2025-65018
https://www.cve.org/CVERecord?id=CVE-2025-65018
https://nvd.nist.gov/vuln/detail/CVE-2025-65018
https://github.com/pnggroup/libpng/commit/16b5e3823918840aae65c0a6da57c78a5a496a4d
https://github.com/pnggroup/libpng/commit/218612ddd6b17944e21eda56caf8b4bf7779d1ea
https://github.com/pnggroup/libpng/issues/755
https://github.com/pnggroup/libpng/pull/757
https://github.com/pnggroup/libpng/security/advisories/GHSA-7wv6-48j4-hj3g
https://access.redhat.com/security/cve/CVE-2025-66293
https://www.cve.org/CVERecord?id=CVE-2025-66293
https://nvd.nist.gov/vuln/detail/CVE-2025-66293
https://github.com/pnggroup/libpng/commit/788a624d7387a758ffd5c7ab010f1870dea753a1
https://github.com/pnggroup/libpng/commit/a05a48b756de63e3234ea6b3b938b8f5f862484a
https://github.com/pnggroup/libpng/issues/764
https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f
Affected packages
Red Hat:rhel_e4s:9.0::appstream
libpng
Package
Name
libpng
Purl
pkg:rpm/redhat/libpng
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-debuginfo
Package
Name
libpng-debuginfo
Purl
pkg:rpm/redhat/libpng-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-debugsource
Package
Name
libpng-debugsource
Purl
pkg:rpm/redhat/libpng-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-devel
Package
Name
libpng-devel
Purl
pkg:rpm/redhat/libpng-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-devel-debuginfo
Package
Name
libpng-devel-debuginfo
Purl
pkg:rpm/redhat/libpng-devel-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-tools-debuginfo
Package
Name
libpng-tools-debuginfo
Purl
pkg:rpm/redhat/libpng-tools-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
Red Hat:rhel_e4s:9.0::baseos
libpng
Package
Name
libpng
Purl
pkg:rpm/redhat/libpng
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-debuginfo
Package
Name
libpng-debuginfo
Purl
pkg:rpm/redhat/libpng-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-debugsource
Package
Name
libpng-debugsource
Purl
pkg:rpm/redhat/libpng-debugsource
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-devel
Package
Name
libpng-devel
Purl
pkg:rpm/redhat/libpng-devel
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-devel-debuginfo
Package
Name
libpng-devel-debuginfo
Purl
pkg:rpm/redhat/libpng-devel-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
libpng-tools-debuginfo
Package
Name
libpng-tools-debuginfo
Purl
pkg:rpm/redhat/libpng-tools-debuginfo
Affected ranges
Type
ECOSYSTEM
Events
Introduced
0
Unknown introduced version / All previous versions are affected
Fixed
2:1.6.37-12.el9_0.1
Database specific
source
"https://security.access.redhat.com/data/osv/RHSA-2026:0234.json"
RHSA-2026:0234 - OSV