RHSA-2026:6732HighCVSS 7.6

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 7, 2026
Last Modified
May 29, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-28162 — libpng: libpng: Denial of Service via buffer overflow in pngimage utility CVE-2025-28164 — libpng: libpng: Denial of Service via buffer overflow in png_create_read_struct() function CVE-2025-64505 — libpng: LIBPNG heap buffer overflow via malformed palette index CVE-2025-64506 — libpng: LIBPNG heap buffer over-read CVE-2025-64720 — libpng: LIBPNG buffer overflow CVE-2025-65018 — libpng: LIBPNG heap buffer overflow CVE-2025-66293 — libpng: LIBPNG out-of-bounds read in png_image_read_composite CVE-2026-3713 — libpng: libpng: Heap-based buffer overflow in pnm2png allows information disclosure and denial of service CVE-2026-22695 — libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read CVE-2026-22801 — libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API CVE-2026-25646 — libpng: LIBPNG has a heap buffer overflow in png_set_quantize CVE-2026-33416 — libpng: libpng: Arbitrary code execution due to use-after-free vulnerability CVE-2026-33636 — libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion

🔗 References (17)