RHSA-2026:6732HighCVSS 7.6

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 7, 2026
Last Modified
August 23, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2025-28162 — libpng: libpng: Denial of Service via buffer overflow in pngimage utility CVE-2025-28164 — libpng: libpng: Denial of Service via buffer overflow in png_create_read_struct() function CVE-2025-64505 — libpng: LIBPNG heap buffer overflow via malformed palette index CVE-2025-64506 — libpng: LIBPNG heap buffer over-read CVE-2025-64720 — libpng: LIBPNG buffer overflow CVE-2025-65018 — libpng: LIBPNG heap buffer overflow CVE-2025-66293 — libpng: LIBPNG out-of-bounds read in png_image_read_composite CVE-2026-3713 — libpng: libpng: Heap-based buffer overflow in pnm2png allows information disclosure and denial of service CVE-2026-22695 — libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read CVE-2026-22801 — libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API CVE-2026-25646 — libpng: LIBPNG has a heap buffer overflow in png_set_quantize CVE-2026-33416 — libpng: libpng: Arbitrary code execution due to use-after-free vulnerability CVE-2026-33636 — libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion

🎯 Affected products4

  • Red Hat Hardened Images
  • libpng-main@aarch64 as a component of Red Hat Hardened Images
  • libpng-main@src as a component of Red Hat Hardened Images
  • libpng-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: To mitigate the risk of denial of service, users should avoid processing untrusted PNG image files with applications that utilize libpng. Exercise caution when opening or viewing PNG files from unknown or suspicious sources. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this vulnerability, avoid processing untrusted image data with the `pnm2png` utility. Restrict execution of `pnm2png` to trusted users and ensure that only trusted image files are processed. Workaround: To mitigate this issue, users should avoid opening untrusted PNG image files. Applications that process PNG images should be configured to restrict processing of untrusted or unverified content where possible. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To reduce exposure, avoid processing untrusted PNG image files with applications that utilize libpng. Restricting the source of PNG images to trusted origins can limit the attack surface.

🔗 References (17)