Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (13)
📋 Description
CVE-2025-28162 — libpng: libpng: Denial of Service via buffer overflow in pngimage utility CVE-2025-28164 — libpng: libpng: Denial of Service via buffer overflow in png_create_read_struct() function CVE-2025-64505 — libpng: LIBPNG heap buffer overflow via malformed palette index CVE-2025-64506 — libpng: LIBPNG heap buffer over-read CVE-2025-64720 — libpng: LIBPNG buffer overflow CVE-2025-65018 — libpng: LIBPNG heap buffer overflow CVE-2025-66293 — libpng: LIBPNG out-of-bounds read in png_image_read_composite CVE-2026-3713 — libpng: libpng: Heap-based buffer overflow in pnm2png allows information disclosure and denial of service CVE-2026-22695 — libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read CVE-2026-22801 — libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API CVE-2026-25646 — libpng: LIBPNG has a heap buffer overflow in png_set_quantize CVE-2026-33416 — libpng: libpng: Arbitrary code execution due to use-after-free vulnerability CVE-2026-33636 — libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion
🔗 References (17)
- selfhttps://access.redhat.com/errata/RHSA-2026:6732
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2025-65018
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2025-64720
- externalhttps://access.redhat.com/security/cve/CVE-2025-64506
- externalhttps://access.redhat.com/security/cve/CVE-2025-64505
- externalhttps://access.redhat.com/security/cve/CVE-2026-22801
- externalhttps://access.redhat.com/security/cve/CVE-2026-22695
- externalhttps://access.redhat.com/security/cve/CVE-2025-28164
- externalhttps://access.redhat.com/security/cve/CVE-2025-28162
- externalhttps://access.redhat.com/security/cve/CVE-2026-33636
- externalhttps://access.redhat.com/security/cve/CVE-2026-33416
- externalhttps://access.redhat.com/security/cve/CVE-2025-66293
- externalhttps://access.redhat.com/security/cve/CVE-2026-3713
- externalhttps://access.redhat.com/security/cve/CVE-2026-25646
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_6732.json