========================================================================== Ubuntu Security Notice USN-8251-1 May 07, 2026 libpng1.6 vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in libpng. Software Description: - libpng1.6: PNG (Portable Network Graphics) file library Details: It was discovered that libpng incorrectly handled memory when processing certain PNG files. If a user or automated system were tricked into opening a specially crafted PNG file, an attacker could use this issue to cause libpng to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-33416) It was discovered that libpng incorrectly handled expanding 8-bit paletted rows to RGB or RGBA on ARM processors. If a user or automated system were tricked into opening a specially crafted PNG file, an attacker could use this issue to cause libpng to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-33636) It was discovered that libpng incorrectly handled certain setter APIs. An attacker could possibly use this issue to obtain sensitive information. (CVE-2026-34757) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.10 libpng16-16t64 1.6.50-1ubuntu0.5 Ubuntu 24.04 LTS libpng16-16t64 1.6.43-5ubuntu0.6 Ubuntu 22.04 LTS libpng16-16 1.6.37-3ubuntu0.5 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-8251-1 CVE-2026-33416, CVE-2026-33636, CVE-2026-34757 Package Information: https://launchpad.net/ubuntu/+source/libpng1.6/1.6.50-1ubuntu0.5 https://launchpad.net/ubuntu/+source/libpng1.6/1.6.43-5ubuntu0.6 https://launchpad.net/ubuntu/+source/libpng1.6/1.6.37-3ubuntu0.5
No comments:
Post a Comment