Opened 5 months ago
Closed 4 months ago
#23307 closed enhancement (fixed)
Fix CVE-2026-40930 in libpng
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
Reported on oss-security earlier today: https://www.openwall.com/lists/oss-security/2026/05/15/21
The fix was addressed in the 1.6.58-apng patch but we use the 1.6.57 patch in the book.
Change History (3)
comment:1 by , 5 months ago
| Owner: | changed from to |
|---|
comment:2 by , 5 months ago
| Owner: | changed from to |
|---|
Note:
See TracTickets
for help on using tickets.

Fixed at f09e85fc50. Leaving open for SA.