CVE-2026-22695
Description
RHSA-2026:4728: libpng security update (Important)
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Mitigation details
Description libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read Red Hat statement This vulnerability is rated Moderate for Red Hat products. A heap buffer over-read flaw exists in the libpng library when processing specially crafted interlaced 16-bit PNG images with 8-bit output format and non-minimal row stride. This issue requires userβ¦
Description
libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
Red Hat statement
This vulnerability is rated Moderate for Red Hat products. A heap buffer over-read flaw exists in the libpng library when processing specially crafted interlaced 16-bit PNG images with 8-bit output format and non-minimal row stride. This issue requires user interaction, as an attacker would need to trick a user into opening a malicious PNG file.
CVSS v3: 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H)
Errata / fixed releases
| Product | Package | Advisory | Released |
|---|---|---|---|
| OPENJDK ELS 11.0.31 | java-11-openjdk-portable | RHSA-2026:9255 | 2026-04-22T00:00:00Z |
| Red Hat Enterprise Linux 10 | libpng-2:1.6.40-8.el10_1.2 | RHSA-2026:3551 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 10.0 Extended Update Support | libpng-2:1.6.40-8.el10_0.2 | RHSA-2026:3577 | 2026-03-03T00:00:00Z |
| Red Hat Enterprise Linux 8 | mingw-libpng-0:1.6.34-2.el8_10 | RHSA-2026:4306 | 2026-03-11T00:00:00Z |
| Red Hat Enterprise Linux 8 | libpng-2:1.6.34-10.el8_10 | RHSA-2026:4728 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | libpng-2:1.6.34-8.el8_2.2 | RHSA-2026:4732 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | libpng-2:1.6.34-8.el8_4.2 | RHSA-2026:4731 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | libpng-2:1.6.34-8.el8_4.2 | RHSA-2026:4731 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | libpng-2:1.6.34-8.el8_6.2 | RHSA-2026:4730 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | libpng-2:1.6.34-8.el8_6.2 | RHSA-2026:4730 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | libpng-2:1.6.34-8.el8_6.2 | RHSA-2026:4730 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | libpng-2:1.6.34-8.el8_8.2 | RHSA-2026:4729 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | libpng-2:1.6.34-8.el8_8.2 | RHSA-2026:4729 | 2026-03-17T00:00:00Z |
| Red Hat Enterprise Linux 9 | libpng-2:1.6.37-12.el9_7.2 | RHSA-2026:3405 | 2026-02-26T00:00:00Z |
| Red Hat Enterprise Linux 9 | libpng-2:1.6.37-12.el9_7.2 | RHSA-2026:3405 | 2026-02-26T00:00:00Z |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | libpng-2:1.6.37-12.el9_0.2 | RHSA-2026:3573 | 2026-03-02T00:00:00Z |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | libpng-2:1.6.37-12.el9_2.2 | RHSA-2026:3575 | 2026-03-03T00:00:00Z |
| Red Hat Enterprise Linux 9.4 Extended Update Support | libpng-2:1.6.37-12.el9_4.2 | RHSA-2026:3574 | 2026-03-03T00:00:00Z |
| Red Hat Enterprise Linux 9.6 Extended Update Support | libpng-2:1.6.37-12.el9_6.2 | RHSA-2026:3576 | 2026-03-03T00:00:00Z |
| Red Hat OpenJDK 11 els for RHEL 7 | java-11-openjdk-1:11.0.31.0.11-1.el7_9 | RHSA-2026:9254 | 2026-04-22T00:00:00Z |
| Red Hat OpenJDK 11 els for RHEL 8 | java-11-openjdk-1:11.0.31.0.11-1.el8 | RHSA-2026:9254 | 2026-04-22T00:00:00Z |
| Red Hat OpenJDK 11 els for RHEL 9 | java-11-openjdk-1:11.0.31.0.11-1.el9 | RHSA-2026:9254 | 2026-04-22T00:00:00Z |
| Red Hat OpenShift Container Platform 4.12 | rhcos-412.86.202604281506-0 | RHSA-2026:12274 | 2026-05-08T00:00:00Z |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-spyre-rhel9:1778244546 | RHSA-2026:16174 | 2026-05-12T00:00:00Z |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-cuda-rhel9:1775680192 | RHSA-2026:8746 | 2026-04-17T00:00:00Z |
| Red Hat AI Inference Server 3.3 | rhaiis/vllm-rocm-rhel9:1775680262 | RHSA-2026:8747 | 2026-04-17T00:00:00Z |
| Red Hat AI Inference Server 3.3 | rhaiis/model-opt-cuda-rhel9:1775749857 | RHSA-2026:8748 | 2026-04-17T00:00:00Z |
| Red Hat Ceph Storage 8 | rhceph/rhceph-8-rhel9:1774002867 | RHSA-2026:5606 | 2026-03-24T00:00:00Z |
| Red Hat Discovery 2 | discovery/discovery-ui-rhel9:1773273070 | RHSA-2026:4501 | 2026-03-12T00:00:00Z |
| Red Hat Hardened Images | libpng-main-1.6.56-1.hum1 | RHSA-2026:6732 | 2026-04-07T00:00:00Z |
Package state
| Product | Package | State |
|---|---|---|
| Red Hat build of OpenJDK 11 ELS | java-21-openjdk-portable | Not affected |
| Red Hat build of OpenJDK 17 | java-17-openjdk-portable | Affected |
| Red Hat build of OpenJDK 17 | java-21-openjdk-portable | Not affected |
| Red Hat build of OpenJDK 1.8 | java-1.8.0-openjdk-portable | Affected |
| Red Hat build of OpenJDK 21 | java-21-openjdk-portable | Affected |
| Red Hat build of OpenJDK 21 | java-21-openjdk-portable-rhel7 | Not affected |
| Red Hat build of OpenJDK 25 | java-21-openjdk-vanilla | Not affected |
| Red Hat build of OpenJDK 25 | java-25-openjdk-portable | Affected |
| Red Hat Enterprise Linux 10 | firefox | Not affected |
| Red Hat Enterprise Linux 10 | java-21-openjdk | Affected |
| Red Hat Enterprise Linux 10 | java-25-openjdk | Affected |
| Red Hat Enterprise Linux 10 | thunderbird | Not affected |
| Red Hat Enterprise Linux 6 | libpng | Affected |
| Red Hat Enterprise Linux 7 | firefox | Not affected |
| Red Hat Enterprise Linux 7 | libpng | Not affected |
| Red Hat Enterprise Linux 7 | libpng12 | Not affected |
| Red Hat Enterprise Linux 8 | firefox | Not affected |
| Red Hat Enterprise Linux 8 | java-17-openjdk | Affected |
| Red Hat Enterprise Linux 8 | java-1.8.0-openjdk | Affected |
| Red Hat Enterprise Linux 8 | java-21-openjdk | Affected |
| Red Hat Enterprise Linux 8 | libpng12 | Not affected |
| Red Hat Enterprise Linux 8 | libpng15 | Not affected |
| Red Hat Enterprise Linux 8 | thunderbird | Not affected |
| Red Hat Enterprise Linux 9 | firefox | Not affected |
| Red Hat Enterprise Linux 9 | java-17-openjdk | Affected |
| Red Hat Enterprise Linux 9 | java-1.8.0-openjdk | Affected |
| Red Hat Enterprise Linux 9 | java-21-openjdk | Affected |
| Red Hat Enterprise Linux 9 | java-25-openjdk | Affected |
| Red Hat Enterprise Linux 9 | libpng15 | Not affected |
| Red Hat Enterprise Linux 9 | thunderbird | Not affected |
Apply commands
yum update -y java
# or:
dnf upgrade -y java
Affected
| Vendor | Product | Version |
|---|---|---|
| redhat | Red Hat build of OpenJDK 11 ELS | Not affected |
| redhat | Red Hat build of OpenJDK 17 | Affected |
| redhat | Red Hat build of OpenJDK 17 | Not affected |
| redhat | Red Hat build of OpenJDK 1.8 | Affected |
| redhat | Red Hat build of OpenJDK 21 | Affected |
| redhat | Red Hat build of OpenJDK 21 | Not affected |
| redhat | Red Hat build of OpenJDK 25 | Not affected |
| redhat | Red Hat build of OpenJDK 25 | Affected |
| redhat | Red Hat Enterprise Linux 10 | Not affected |
| redhat | Red Hat Enterprise Linux 10 | Affected |
| redhat | Red Hat Enterprise Linux 10 | Affected |
| redhat | Red Hat Enterprise Linux 10 | Not affected |
| redhat | Red Hat Enterprise Linux 6 | Affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 7 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 8 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Affected |
| redhat | Red Hat Enterprise Linux 9 | Affected |
| redhat | Red Hat Enterprise Linux 9 | Affected |
| redhat | Red Hat Enterprise Linux 9 | Affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
| redhat | Red Hat Enterprise Linux 9 | Not affected |
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| rocky | 8 | fixed | |
| rhel | 9 | fixed | |
| debian | bookworm | fixed | 1.6.39-2+deb12u2 |
| debian | bullseye | fixed | 1.6.37-3+deb11u2 |
| debian | forky | fixed | 1.6.54-1 |
| debian | sid | fixed | 1.6.54-1 |
| debian | trixie | fixed | 1.6.48-1+deb13u2 |
| sles | affected | | |
| rocky | 9 | fixed | |
| almalinux | 9 | fixed | libpng-devel-1.6.37-12.el9_7.2.aarch64.rpm |
| rhel | 8 | fixed | |
References
- https://errata.rockylinux.org/RLSA-2026:4728
- https://errata.rockylinux.org/RLSA-2026:4306
- https://access.redhat.com/errata/RHSA-2026:3405
- https://security-tracker.debian.org/tracker/CVE-2026-22695
- https://www.suse.com/security/cve/CVE-2026-22695.html
- https://errata.rockylinux.org/RLSA-2026:3405
- https://access.redhat.com/errata/RHSA-2026:4306
- https://bugzilla.redhat.com/2428824
- https://bugzilla.redhat.com/2428825
- https://bugzilla.redhat.com/2438542
- https://errata.almalinux.org/8/ALSA-2026-4306.html
- https://access.redhat.com/errata/RHSA-2026:4728
- https://errata.almalinux.org/8/ALSA-2026-4728.html
- https://errata.almalinux.org/9/ALSA-2026-3405.html
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.