Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2026-25646

PUBLISHED 30.06.2026

CNA: GitHub_M

LIBPNG has a heap buffer overflow in png_set_quantize

Обновлено: 10.02.2026
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user's display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.

CWE

Идентификатор Описание
CWE-122 A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
CWE-126 The product reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer.

CVSS

Оценка Severity Версия Базовый вектор
8.3 HIGH 4.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

EPSS

Вероятность Severity Процентиль ? Дата расчёта
0.08% LOW 23.66 23.05.2026

Доп. Информация

Product Status

libpng
Product: libpng
Vendor: pnggroup
Default status: Не определен
Версии:
Затронутые версии Статус
Наблюдалось в версии < 1.6.55 affected
 

Ссылки

CVE Program Container

Обновлено: 10.02.2026
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

Ссылки

CISA ADP Vulnrichment

Обновлено: 11.02.2026
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
poc no partial 2.0.3 11.02.2026

Ссылки

libpng: LIBPNG has a heap buffer overflow in png_set_quantize

Обновлено: 30.06.2026

CVSS

Оценка Severity Версия Базовый вектор
7 HIGH 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Ссылки

https://access.redhat.com/security/cve/CVE-2026-25646
https://bugzilla.redhat.com/show_bug.cgi?id=2438542
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25646.json
https://access.redhat.com/errata/RHSA-2026:4756
https://access.redhat.com/errata/RHSA-2026:7032
https://access.redhat.com/errata/RHSA-2026:9254
https://access.redhat.com/errata/RHSA-2026:12274
https://access.redhat.com/errata/RHSA-2026:7239
https://access.redhat.com/errata/RHSA-2026:15087
https://access.redhat.com/errata/RHSA-2026:14773
https://access.redhat.com/errata/RHSA-2026:10097
https://access.redhat.com/errata/RHSA-2026:17596
https://access.redhat.com/errata/RHSA-2026:6553
https://access.redhat.com/errata/RHSA-2026:7243
https://access.redhat.com/errata/RHSA-2026:3577
https://access.redhat.com/errata/RHSA-2026:3551
https://access.redhat.com/errata/RHSA-2026:9686
https://access.redhat.com/errata/RHSA-2026:6445
https://access.redhat.com/errata/RHSA-2026:6439
https://access.redhat.com/errata/RHSA-2026:7035
https://access.redhat.com/errata/RHSA-2026:6466
https://access.redhat.com/errata/RHSA-2026:7036
https://access.redhat.com/errata/RHSA-2026:6467
https://access.redhat.com/errata/RHSA-2026:7033
https://access.redhat.com/errata/RHSA-2026:6469
https://access.redhat.com/errata/RHSA-2026:7034
https://access.redhat.com/errata/RHSA-2026:6468
https://access.redhat.com/errata/RHSA-2026:3573
https://access.redhat.com/errata/RHSA-2026:4222
https://access.redhat.com/errata/RHSA-2026:3575
https://access.redhat.com/errata/RHSA-2026:4221
https://access.redhat.com/errata/RHSA-2026:3574
https://access.redhat.com/errata/RHSA-2026:3969
https://access.redhat.com/errata/RHSA-2026:3576
https://access.redhat.com/errata/RHSA-2026:3968
https://access.redhat.com/errata/RHSA-2026:3405
https://access.redhat.com/errata/RHSA-2026:3031
https://access.redhat.com/errata/RHSA-2026:4728
https://access.redhat.com/errata/RHSA-2026:4732
https://access.redhat.com/errata/RHSA-2026:4731
https://access.redhat.com/errata/RHSA-2026:4730
https://access.redhat.com/errata/RHSA-2026:4729
https://access.redhat.com/errata/RHSA-2026:4306
https://access.redhat.com/errata/RHSA-2026:9255
https://access.redhat.com/errata/RHSA-2026:8748
https://access.redhat.com/errata/RHSA-2026:8746
https://access.redhat.com/errata/RHSA-2026:8747
https://access.redhat.com/errata/RHSA-2026:16174
https://access.redhat.com/errata/RHSA-2026:9687
https://access.redhat.com/errata/RHSA-2026:5606
https://access.redhat.com/errata/RHSA-2026:4501
https://access.redhat.com/errata/RHSA-2026:6732

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.