CVE-2026-25646: CWE-122: Heap-based Buffer Overflow in pnggroup libpng
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.
AI Analysis
Technical Summary
CVE-2026-25646 is a heap-based buffer overflow vulnerability in the libpng library's png_set_quantize() function. When invoked without a histogram and with a palette exceeding twice the maximum colors supported by the display, certain valid PNG palettes trigger an infinite loop that reads out-of-bounds from an internal heap buffer. This vulnerability is present in libpng versions prior to 1.6.55 and has been assigned a CVSS score of 8.3 (high severity). The issue is fixed in version 1.6.55. Red Hat has issued security advisories and patches for affected Red Hat Enterprise Linux Extended Life Cycle Support 7 packages.
Potential Impact
The vulnerability can lead to a heap-based buffer overflow, potentially causing application crashes or memory corruption when processing crafted PNG images. This may allow an attacker to disrupt service or possibly execute arbitrary code depending on the context of the vulnerable application. The vulnerability affects all applications using libpng versions before 1.6.55 that call the png_set_quantize() function under the described conditions.
Mitigation Recommendations
An official fix is available in libpng version 1.6.55. Users and administrators should upgrade to version 1.6.55 or later to remediate this vulnerability. Red Hat has released security updates for affected Red Hat Enterprise Linux 7 Extended Life Cycle Support packages. Applying these vendor-provided patches is the recommended mitigation. Patch status is confirmed by the vendor advisory.
CVE-2026-25646: CWE-122: Heap-based Buffer Overflow in pnggroup libpng
Description
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-25646 is a heap-based buffer overflow vulnerability in the libpng library's png_set_quantize() function. When invoked without a histogram and with a palette exceeding twice the maximum colors supported by the display, certain valid PNG palettes trigger an infinite loop that reads out-of-bounds from an internal heap buffer. This vulnerability is present in libpng versions prior to 1.6.55 and has been assigned a CVSS score of 8.3 (high severity). The issue is fixed in version 1.6.55. Red Hat has issued security advisories and patches for affected Red Hat Enterprise Linux Extended Life Cycle Support 7 packages.
Potential Impact
The vulnerability can lead to a heap-based buffer overflow, potentially causing application crashes or memory corruption when processing crafted PNG images. This may allow an attacker to disrupt service or possibly execute arbitrary code depending on the context of the vulnerable application. The vulnerability affects all applications using libpng versions before 1.6.55 that call the png_set_quantize() function under the described conditions.
Mitigation Recommendations
An official fix is available in libpng version 1.6.55. Users and administrators should upgrade to version 1.6.55 or later to remediate this vulnerability. Red Hat has released security updates for affected Red Hat Enterprise Linux 7 Extended Life Cycle Support packages. Applying these vendor-provided patches is the recommended mitigation. Patch status is confirmed by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:7036
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a1f4e85e29bf47b5007e0b6
Added to database: 06/02/2026, 21:43:33 UTC
Last enriched: 07/15/2026, 16:04:18 UTC
Last updated: 09/10/2026, 22:11:51 UTC
Views: 71
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.