Attachments (1)
Change History (9)
comment:1 by , 10 months ago
| Milestone: | 12.5 → 99-Waiting |
|---|---|
| Summary: | libpng-1.6.53 → libpng-1.6.53 (wait for next version) |
comment:2 by , 9 months ago
| Milestone: | 99-Waiting → 12.5 |
|---|---|
| Summary: | libpng-1.6.53 (wait for next version) → libpng-1.6.54 |
comment:3 by , 9 months ago
| Priority: | normal → elevated |
|---|
There are some security fixes here:
---
libpng versions 1.6.26 through 1.6.53 have one or both of a pair of recently discovered security vulnerabilities:
- CVE-2026-22695 (moderate severity): Heap buffer over-read in the libpng simplified API function png_image_finish_read() when processing interlaced 16-bit PNGs with 8-bit output format and non-minimal row stride. This is a regression introduced by the fix for CVE-2025-65018 in libpng 1.6.51.
- CVE-2026-22801 (moderate severity): Integer truncation in the libpng simplified write API functions png_write_image_16bit() and png_write_image_8bit() causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems.
by , 9 months ago
| Attachment: | libpng-1.6.54-apng.patch added |
|---|
Refactored apng patch for libpng-1.6.54
comment:4 by , 9 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
Note:
See TracTickets
for help on using tickets.

1.6.53 fixes the build with RISC-V RVV and Windows VC++ w/ CMake. Since we focus on the x86 family, we should be safe from this. No security fixes with this release. Confirmed doing a diff -Naurp.