CVE-2026-33636: CWE-125: Out-of-bounds Read in pnggroup libpng
An out-of-bounds read and write vulnerability exists in libpng versions 1.6.36 through 1.6.55 in the ARM/AArch64 Neon-optimized palette expansion code. This occurs when expanding 8-bit paletted rows to RGB or RGBA, where the Neon loop processes a final partial chunk without verifying input pixel boundaries, causing pointer underflow and memory corruption. The issue can be triggered by decoding attacker-controlled PNG files if Neon is enabled. Version 1.6.56 addresses this vulnerability.
AI Analysis
Technical Summary
The vulnerability in libpng affects the ARM/AArch64 Neon-optimized palette expansion path used during decoding of 8-bit paletted PNG images. Specifically, the Neon loop processes the final partial chunk of pixels without confirming that sufficient input pixels remain, leading to out-of-bounds reads and writes by dereferencing pointers before the start of the row buffer. This memory corruption can be triggered by normal decoding of malicious PNG files when Neon optimizations are enabled. The flaw is present in libpng versions from 1.6.36 up to but not including 1.6.56. The issue is fixed in version 1.6.56.
Potential Impact
Successful exploitation can lead to memory corruption due to out-of-bounds read and write operations. The CVSS score of 7.6 indicates high severity with potential impacts including limited confidentiality and integrity loss, and high impact on availability. This could cause application crashes or potentially enable further exploitation depending on the context of use.
Mitigation Recommendations
Upgrade libpng to version 1.6.56 or later, where this vulnerability is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor's versioning information.
CVE-2026-33636: CWE-125: Out-of-bounds Read in pnggroup libpng
Description
An out-of-bounds read and write vulnerability exists in libpng versions 1.6.36 through 1.6.55 in the ARM/AArch64 Neon-optimized palette expansion code. This occurs when expanding 8-bit paletted rows to RGB or RGBA, where the Neon loop processes a final partial chunk without verifying input pixel boundaries, causing pointer underflow and memory corruption. The issue can be triggered by decoding attacker-controlled PNG files if Neon is enabled. Version 1.6.56 addresses this vulnerability.
CVSS v3.1
Score 7.6high
Affected software
pkg:github/pnggroup/libpngRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in libpng affects the ARM/AArch64 Neon-optimized palette expansion path used during decoding of 8-bit paletted PNG images. Specifically, the Neon loop processes the final partial chunk of pixels without confirming that sufficient input pixels remain, leading to out-of-bounds reads and writes by dereferencing pointers before the start of the row buffer. This memory corruption can be triggered by normal decoding of malicious PNG files when Neon optimizations are enabled. The flaw is present in libpng versions from 1.6.36 up to but not including 1.6.56. The issue is fixed in version 1.6.56.
Potential Impact
Successful exploitation can lead to memory corruption due to out-of-bounds read and write operations. The CVSS score of 7.6 indicates high severity with potential impacts including limited confidentiality and integrity loss, and high impact on availability. This could cause application crashes or potentially enable further exploitation depending on the context of use.
Mitigation Recommendations
Upgrade libpng to version 1.6.56 or later, where this vulnerability is fixed. No other mitigations are indicated. Patch status is confirmed by the vendor's versioning information.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-23T14:24:11.619Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 69c569d6f4197a8e3be94d98
Added to database: 03/26/2026, 17:16:06 UTC
Last enriched: 05/26/2026, 22:23:30 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 233
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.