CVE-2025-66293

high
Published 2026-01-07 · Modified 2026-05-26
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk
8.0

Description

RHSA-2026:9686: java-17-openjdk security update (Important)

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata — Red Hat Inc. · View original ↗ · Open-Errata-API

Description libpng: LIBPNG out-of-bounds read in png_image_read_composite Red Hat statement The Red Hat Product Security team has rated this vulnerability as Important as it affects libpng, a widely used library for PNG image processing. The flaw is due to an out-of-bounds read in libpng’s simplified API when handling specially crafted PNG images containing partial transparency and gamma…

Description

libpng: LIBPNG out-of-bounds read in png_image_read_composite

Red Hat statement

The Red Hat Product Security team has rated this vulnerability as Important as it affects libpng, a widely used library for PNG image processing. The flaw is due to an out-of-bounds read in libpng’s simplified API when handling specially crafted PNG images containing partial transparency and gamma correction data. Successful exploitation could result in information disclosure or cause application crashes in applications processing untrusted PNG content. For `java-17-openjdk-headless` and `java-21-openjdk-headless`, while the affected code is present in the bundled sources, it is not exercised by these headless packages.

CVSS v3: 7.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
OPENJDK ELS 11.0.31java-11-openjdk-portableRHSA-2026:92552026-04-22T00:00:00Z
Red Hat Enterprise Linux 10libpng-2:1.6.40-8.el10_1.1RHSA-2026:02372026-01-07T00:00:00Z
Red Hat Enterprise Linux 10.0 Extended Update Supportlibpng-2:1.6.40-8.el10_0.1RHSA-2026:02122026-01-07T00:00:00Z
Red Hat Enterprise Linux 8mingw-libpng-0:1.6.34-1.el8_10RHSA-2026:01252026-01-06T00:00:00Z
Red Hat Enterprise Linux 8libpng-2:1.6.34-9.el8_10RHSA-2026:02412026-01-07T00:00:00Z
Red Hat Enterprise Linux 8.2 Advanced Update Supportlibpng-2:1.6.34-8.el8_2.1RHSA-2026:03232026-01-08T00:00:00Z
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Supportlibpng-2:1.6.34-8.el8_4.1RHSA-2026:03212026-01-08T00:00:00Z
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-Onlibpng-2:1.6.34-8.el8_4.1RHSA-2026:03212026-01-08T00:00:00Z
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Supportlibpng-2:1.6.34-8.el8_6.1RHSA-2026:03222026-01-08T00:00:00Z
Red Hat Enterprise Linux 8.6 Telecommunications Update Servicelibpng-2:1.6.34-8.el8_6.1RHSA-2026:03222026-01-08T00:00:00Z
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutionslibpng-2:1.6.34-8.el8_6.1RHSA-2026:03222026-01-08T00:00:00Z
Red Hat Enterprise Linux 8.8 Telecommunications Update Servicelibpng-2:1.6.34-8.el8_8.1RHSA-2026:03132026-01-08T00:00:00Z
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutionslibpng-2:1.6.34-8.el8_8.1RHSA-2026:03132026-01-08T00:00:00Z
Red Hat Enterprise Linux 9libpng-2:1.6.37-12.el9_7.1RHSA-2026:02382026-01-07T00:00:00Z
Red Hat Enterprise Linux 9libpng-2:1.6.37-12.el9_7.1RHSA-2026:02382026-01-07T00:00:00Z
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutionslibpng-2:1.6.37-12.el9_0.1RHSA-2026:02342026-01-07T00:00:00Z
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutionslibpng-2:1.6.37-12.el9_2.1RHSA-2026:02162026-01-07T00:00:00Z
Red Hat Enterprise Linux 9.4 Extended Update Supportlibpng-2:1.6.37-12.el9_4.1RHSA-2026:02112026-01-07T00:00:00Z
Red Hat Enterprise Linux 9.6 Extended Update Supportlibpng-2:1.6.37-12.el9_6.1RHSA-2026:02102026-01-07T00:00:00Z
Red Hat OpenJDK 11 els for RHEL 7java-11-openjdk-1:11.0.31.0.11-1.el7_9RHSA-2026:92542026-04-22T00:00:00Z
Red Hat OpenJDK 11 els for RHEL 8java-11-openjdk-1:11.0.31.0.11-1.el8RHSA-2026:92542026-04-22T00:00:00Z
Red Hat OpenJDK 11 els for RHEL 9java-11-openjdk-1:11.0.31.0.11-1.el9RHSA-2026:92542026-04-22T00:00:00Z
Red Hat OpenShift Container Platform 4.12rhcos-412.86.202603041314-0RHSA-2026:38612026-03-12T00:00:00Z
Red Hat OpenShift Container Platform 4.13rhcos-413.92.202602240113-0RHSA-2026:34152026-03-05T00:00:00Z
Red Hat OpenShift Container Platform 4.14rhcos-414.92.202602171627-0RHSA-2026:29742026-02-26T00:00:00Z
Red Hat OpenShift Container Platform 4.15rhcos-415.92.202603101737-0RHSA-2026:44192026-03-19T00:00:00Z
Red Hat OpenShift Container Platform 4.16rhcos-416.94.202602101357-0RHSA-2026:26592026-02-18T00:00:00Z
Red Hat OpenShift Container Platform 4.17rhcos-417.94.202602090846-0RHSA-2026:26712026-02-18T00:00:00Z
Red Hat OpenShift Container Platform 4.18rhcos-418.94.202602022246-0RHSA-2026:20722026-02-11T00:00:00Z
Red Hat OpenShift Container Platform 4.19rhcos-4.19.9.6.202602112047-0RHSA-2026:26332026-02-18T00:00:00Z
Red Hat Discovery 2discovery/discovery-ui-rhel9:1767904573RHSA-2026:04142026-01-08T00:00:00Z
Red Hat Hardened Imageslibpng-main-1.6.56-1.hum1RHSA-2026:67322026-04-07T00:00:00Z

Package state

ProductPackageState
Red Hat build of OpenJDK 11 ELSjava-21-openjdk-portableNot affected
Red Hat build of OpenJDK 17java-17-openjdk-portableAffected
Red Hat build of OpenJDK 17java-21-openjdk-portableNot affected
Red Hat build of OpenJDK 1.8java-1.8.0-openjdk-portableAffected
Red Hat build of OpenJDK 21java-21-openjdk-portableAffected
Red Hat build of OpenJDK 21java-21-openjdk-portable-rhel7Not affected
Red Hat build of OpenJDK 25java-21-openjdk-vanillaNot affected
Red Hat build of OpenJDK 25java-25-openjdk-portableAffected
Red Hat Enterprise Linux 10firefoxNot affected
Red Hat Enterprise Linux 10java-21-openjdkAffected
Red Hat Enterprise Linux 10java-25-openjdkAffected
Red Hat Enterprise Linux 10thunderbirdNot affected
Red Hat Enterprise Linux 6libpngWill not fix
Red Hat Enterprise Linux 7firefoxNot affected
Red Hat Enterprise Linux 7java-11-openjdkNot affected
Red Hat Enterprise Linux 7libpngNot affected
Red Hat Enterprise Linux 7libpng12Not affected
Red Hat Enterprise Linux 8firefoxNot affected
Red Hat Enterprise Linux 8java-17-openjdkAffected
Red Hat Enterprise Linux 8java-1.8.0-openjdkAffected
Red Hat Enterprise Linux 8java-21-openjdkAffected
Red Hat Enterprise Linux 8libpng12Not affected
Red Hat Enterprise Linux 8libpng15Not affected
Red Hat Enterprise Linux 8thunderbirdNot affected
Red Hat Enterprise Linux 9firefoxNot affected
Red Hat Enterprise Linux 9java-17-openjdkAffected
Red Hat Enterprise Linux 9java-1.8.0-openjdkAffected
Red Hat Enterprise Linux 9java-21-openjdkAffected
Red Hat Enterprise Linux 9libpng15Not affected
Red Hat Enterprise Linux 9thunderbirdNot affected

Apply commands

bash fix
Apply RHSA-2026:9255 for OPENJDK ELS 11.0.31
yum update -y java
# or:
dnf upgrade -y java

Affected

VendorProductVersion
redhatRed Hat build of OpenJDK 11 ELSNot affected
redhatRed Hat build of OpenJDK 17Affected
redhatRed Hat build of OpenJDK 17Not affected
redhatRed Hat build of OpenJDK 1.8Affected
redhatRed Hat build of OpenJDK 21Affected
redhatRed Hat build of OpenJDK 21Not affected
redhatRed Hat build of OpenJDK 25Not affected
redhatRed Hat build of OpenJDK 25Affected
redhatRed Hat Enterprise Linux 10Not affected
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 10Affected
redhatRed Hat Enterprise Linux 10Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 8Not affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat Enterprise Linux 9Affected
redhatRed Hat Enterprise Linux 9Not affected
redhatRed Hat Enterprise Linux 9Not affected

OS impact

OSVersionStatusFixed in
rockylinux rocky8fixed
redhat rhel9fixed
debian debianbookwormfixed1.6.39-2+deb12u1
debian debianbullseyefixed1.6.37-3+deb11u1
debian debianforkyfixed1.6.52-1
debian debiansidfixed1.6.52-1
debian debiantrixiefixed1.6.48-1+deb13u1
suse slesaffected
rockylinux rocky9fixed

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.