RLSA-2026:3031

Source
https://errata.rockylinux.org/RLSA-2026:3031
Import Source
https://storage.googleapis.com/resf-osv-data/RLSA-2026:3031.json
JSON Data
https://api.test.osv.dev/v1/vulns/RLSA-2026:3031
Upstream
Published
2026-02-24T18:54:11.875441Z
Modified
2026-02-25T00:46:04.586889Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H CVSS Calculator
Summary
Important: libpng15 security update
Details

The libpng15 package provides libpng 1.5, an older version of the libpng. library for manipulating PNG (Portable Network Graphics) image format files. This version should be used only if you are unable to use the current version of libpng.

Security Fix(es):

  • libpng: LIBPNG has a heap buffer overflow in pngsetquantize (CVE-2026-25646)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References
Credits
    • Rocky Enterprise Software Foundation
    • Red Hat

Affected packages

Rocky Linux:9 / libpng15

Package

Name
libpng15
Purl
pkg:rpm/rocky-linux/libpng15?distro=rocky-linux-9&epoch=0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0:1.5.30-14.el9_7.1
Database specific
{
    "yum_repository": "AppStream"
}

Database specific

source
"https://storage.googleapis.com/resf-osv-data/RLSA-2026:3031.json"