ALSA-2026:0125

Source
https://errata.almalinux.org/8/ALSA-2026-0125.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:0125.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALSA-2026:0125
Related
Published
2026-01-06T00:00:00Z
Modified
2026-01-13T10:03:46.664941Z
Summary
Important: mingw-libpng security update
Details

MinGW Windows Libpng library.

Security Fix(es):

  • libpng: LIBPNG buffer overflow (CVE-2025-64720)
  • libpng: LIBPNG heap buffer overflow (CVE-2025-65018)
  • libpng: LIBPNG out-of-bounds read in pngimageread_composite (CVE-2025-66293)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:8 / mingw32-libpng

Package

Name
mingw32-libpng
Purl
pkg:rpm/almalinux/mingw32-libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.34-1.el8_10

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:0125.json"

AlmaLinux:8 / mingw32-libpng-static

Package

Name
mingw32-libpng-static
Purl
pkg:rpm/almalinux/mingw32-libpng-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.34-1.el8_10

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:0125.json"

AlmaLinux:8 / mingw64-libpng

Package

Name
mingw64-libpng
Purl
pkg:rpm/almalinux/mingw64-libpng

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.34-1.el8_10

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:0125.json"

AlmaLinux:8 / mingw64-libpng-static

Package

Name
mingw64-libpng-static
Purl
pkg:rpm/almalinux/mingw64-libpng-static

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.6.34-1.el8_10

Database specific

source

"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2026:0125.json"