vulnerability

Ubuntu: (Multiple Advisories) (CVE-2026-22801): libpng vulnerabilities

Severity
6
CVSS
(AV:L/AC:L/Au:N/C:P/I:N/A:C)
Published
Jan 12, 2026
Added
Jan 15, 2026
Modified
Feb 13, 2026

Description

It was discovered that the libpng simplified API incorrectly processed
palette PNG images with partial transparency and gamma correction. If a
user or automated system were tricked into opening a specially crafted PNG
file, an attacker could use this issue to cause libpng to crash, resulting
in a denial of service. (CVE-2025-66293)

Petr Simecek, Stanislav Fort and Pavel Kohout discovered that the libpng
simplified API incorrectly processed interlaced 16-bit PNGs with 8-bit
output format and non-minimal row strides. If a user or automated system
were tricked into opening a specially crafted PNG file, an attacker could
use this issue to cause libpng to crash, resulting in a denial of service.
(CVE-2026-22695)

Cosmin Truta discovered that the libpng simplified API incorrectly handled
invalid row strides. If a user or automated system were tricked into
opening a specially crafted PNG file, an attacker could use this issue to
cause libpng to crash, resulting in a denial of service. (CVE-2026-22801)

Solutions

ubuntu-pro-upgrade-libpng16-16ubuntu-pro-upgrade-libpng16-16t64
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.