RLSA-2026:26347

Source
https://errata.rockylinux.org/RLSA-2026:26347
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:26347.json
JSON Data
https://api.test.osv.dev/v1/vulns/RLSA-2026:26347
Upstream
Published
2026-06-17T06:00:26.379988Z
Modified
2026-06-17T06:30:05.400694178Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Moderate: libpng15 security update
Details

The libpng15 package provides libpng 1.5, an older version of the libpng. library for manipulating PNG (Portable Network Graphics) image format files. This version should be used only if you are unable to use the current version of libpng.

Security Fix(es):

  • libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:8 / libpng15

Package

Name
libpng15
Purl
pkg:rpm/rocky-linux/libpng15?distro=rocky-linux-8&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:1.5.30-9.el8_10
Database specific
{
    "yum_repository": "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:26347.json"