Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade libpng-debuginfoUpgrade libpng-tools-debuginfoUpgrade libpng-devel-debuginfoUpgrade libpngUpgrade libpng-staticUpgrade libpng-toolsUpgrade libpng-develUpgrade libpng-debugsource | Feb 20, 2026 | Jan 27, 2026 |
| Debian | — | Upgrade libpng1.6 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Jan 27, 2026 |
| Ubuntu | — | Upgrade libpng16-16t64 | Feb 3, 2026 | Jan 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub