Opened 6 months ago

Closed 6 months ago

#23118 closed enhancement (fixed)

libpng-1.6.57

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (7)

comment:1 by Douglas R. Reno, 6 months ago

Priority: normal → elevated

This release fixes regressions over 1.6.56 and a security fix.

Hello there!

Remember those load-bearing TODO comments from the 1.6.56 announcement? The
ones that said *"Fix this"* for 25 years? Well, fixing them introduced a
new problem. The irony has still not finished writing itself.

CVE-2026-34757 is a medium-severity use-after-free vulnerability in the
chunk setter API. The PLTE and tRNS variants are regressions from the
CVE-2026-33416 fix in 1.6.56. While investigating those, we found an older
variant in the histogram setter that has been present since 1.0.9. The
common pattern: passing a pointer obtained from a getter back into the
corresponding setter causes the setter to free the buffer it's about to
read from. The good news is that this one cannot be triggered by a crafted
PNG alone; it requires the application to call the getter and setter in a
specific sequence.

Many thanks to @Iv4n550 for reporting the regressions.

This release also hardens the append-style setters against a theoretical
variant of the same aliasing pattern, and fixes an integer overflow in the
rowbytes computation (contributed by Mohammad Seet).

and from ANNOUNCE:

Changes from version 1.6.56 to version 1.6.57
---------------------------------------------

 * Fixed CVE-2026-34757 (medium severity):
   Use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST`
   leading to corrupted chunk data and potential heap information disclosure.
   Also hardened the append-style setters (`png_set_text`, `png_set_sPLT`,
   `png_set_unknown_chunks`) against a theoretical variant of the same
   aliasing pattern.
   (Reported by Iv4n <Iv4n550@users.noreply.github.com>.)
 * Fixed integer overflow in rowbytes computation in read transforms.
   (Contributed by Mohammad Seet.)

I agree with the assessment regarding the CVE being assigned Medium.

comment:2 by Joe Locash, 6 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 6 months ago

The apng patch for .56 fails in 2 hunks and there is no patch for .57 yet. If a new patch isn't available soon I'll get the patch working with .57.

comment:4 by Joe Locash, 6 months ago

Fixed at 2727c8fe57. Leaving open for SA.

comment:5 by Joe Locash, 6 months ago

Owner: changed from Joe Locash to Douglas R. Reno
Status: assigned → new

comment:6 by Bruce Dubbs, 6 months ago

Owner: changed from Douglas R. Reno to SecurityAdvisory

comment:7 by Douglas R. Reno, 6 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-047 issued

Note: See TracTickets for help on using tickets.