Opened 6 months ago

Closed 6 months ago

#23038 closed enhancement (fixed)

libpng-1.6.56

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: high Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (3)

comment:1 by Douglas R. Reno, 6 months ago

Priority: normal → high

Another security release, and just like other ones recently, it's quite serious.

Hello, everyone,

libpng 1.6.56 is out, and it's another security release. Two high-severity
CVEs this time -- or, in other words, it's "business-as-usual".

The first one is a... story. CVE-2026-33416 is a use-after-free
vulnerability that has been hiding in the transparency and palette handling
code since the 1990s. Two internal buffers were shared between two data
structures with independent lifetimes. The code knew this was wrong. A TODO
comment said: *"this is a horrible side effect [...] Fix this."* Another
one said: *"CONSIDER: Fix this by not sharing the palette in this way."*
Nobody fixed it, because the side effects were load-bearing. For about 25
years. (That's 5 years younger than the age of that other bug that we
swatted in that other v1.6.55 release.)

Two independent researchers, working continents apart and unaware of each
other, found it within days of each other. Halil Oktay, somewhere in
Poland, discovered the vulnerability and contributed the fix. Ryo Shimada,
somewhere in Japan, independently discovered the same vulnerability and
demonstrated arbitrary code execution with an RCE exploit. The triggering
PNG is 100% standards-compliant. No validator rejects it. No application
firewall catches it. Oh, well...

The second one is CVE-2026-33636, an out-of-bounds read and write
vulnerability in the ARM Neon palette expansion code. This one has been
around since libpng 1.6.36. Many thanks to Taegu Ha for reporting it and
contributing the fix, from somewhere in Korea.

If you process untrusted PNG images with libpng, you need this update.
CVE-2026-33416 affects all libpng versions on all platforms. CVE-2026-33636
affects libpng 1.6.36 through 1.6.55, on ARM and AArch64 with Neon enabled.

The gory details are available at:

https://github.com/pnggroup/libpng/security/advisories/GHSA-m4pc-p4q3-4c7j
https://github.com/pnggroup/libpng/security/advisories/GHSA-wjr5-c57x-95m2
https://github.com/pnggroup/libpng/blob/v1.6.56/ANNOUNCE

CVE-2026-33416 has a working exploit that explicitly causes remote code execution on glibc-based systems. The triggering PNG file is 100% valid too...

comment:2 by Douglas R. Reno, 6 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:3 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at ee4e9567de87f3fdd4931fbf5b13a344cfbb7e84

SA-13.0-016 issued

Note: See TracTickets for help on using tickets.