libpng-1.6.37-15.el9_8.2
エラータID: AXSA:2026-1378:13
リリース日:
2026/07/29 Wednesday - 17:22
題名:
libpng-1.6.37-15.el9_8.2
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
Moderate
Description:
以下項目について対処しました。
[Security Fix]
- libpng には、メモリ領域の解放後利用の問題があるため、リモート
の攻撃者により、任意のコードの実行、およびサービス拒否攻撃を可能
とする脆弱性が存在します。(CVE-2026-33416)
- libpng には、メモリ領域の範囲外アクセスの問題があるため、
リモートの攻撃者により、情報の漏洩、データ破壊、およびサービス
拒否攻撃を可能とする脆弱性が存在します。(CVE-2026-33636)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-33416
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two structs with independent lifetimes. The `trans_alpha` aliasing has been present since at least libpng 1.0, and the `palette` aliasing since at least 1.2.1. Both affect all prior release lines `png_set_tRNS` sets `png_ptr->trans_alpha = info_ptr->trans_alpha` (256-byte buffer) and `png_set_PLTE` sets `info_ptr->palette = png_ptr->palette` (768-byte buffer). In both cases, calling `png_free_data` (with `PNG_FREE_TRNS` or `PNG_FREE_PLTE`) frees the buffer through `info_ptr` while the corresponding `png_ptr` pointer remains dangling. Subsequent row-transform functions dereference and, in some code paths, write to the freed memory. A second call to `png_set_tRNS` or `png_set_PLTE` has the same effect, because both functions call `png_free_data` internally before reallocating the `info_ptr` buffer. Version 1.6.56 fixes the issue.
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.2.1 through 1.6.55, `png_set_tRNS` and `png_set_PLTE` each alias a heap-allocated buffer between `png_struct` and `png_info`, sharing a single allocation across two structs with independent lifetimes. The `trans_alpha` aliasing has been present since at least libpng 1.0, and the `palette` aliasing since at least 1.2.1. Both affect all prior release lines `png_set_tRNS` sets `png_ptr->trans_alpha = info_ptr->trans_alpha` (256-byte buffer) and `png_set_PLTE` sets `info_ptr->palette = png_ptr->palette` (768-byte buffer). In both cases, calling `png_free_data` (with `PNG_FREE_TRNS` or `PNG_FREE_PLTE`) frees the buffer through `info_ptr` while the corresponding `png_ptr` pointer remains dangling. Subsequent row-transform functions dereference and, in some code paths, write to the freed memory. A second call to `png_set_tRNS` or `png_set_PLTE` has the same effect, because both functions call `png_free_data` internally before reallocating the `info_ptr` buffer. Version 1.6.56 fixes the issue.
CVE-2026-33636
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.
追加情報:
N/A
ダウンロード:
SRPMS
- libpng-1.6.37-15.el9_8.2.src.rpm
MD5: 1426539d42fa5ef17138ed5245ef3e15
SHA-256: ef866255a3f995303df0bad2ffc2684009308d73716b4aae824762fbe6059483
Size: 1.47 MB
Asianux Server 9 for x86_64
- libpng-1.6.37-15.el9_8.2.i686.rpm
MD5: 844fad844e2e00ca701435a1203ca83a
SHA-256: b1a3c7a3fe7fc698198180f782e02f7730372ac9083c6a845cff194cd088e6e0
Size: 124.32 kB - libpng-1.6.37-15.el9_8.2.x86_64.rpm
MD5: eefb75c0d39b428ce498e5bb5a501d04
SHA-256: ac9b2a5d38c16166380db48672f51b71b58c74602f5f1d7e1fe8a3211cd66635
Size: 115.89 kB - libpng-devel-1.6.37-15.el9_8.2.i686.rpm
MD5: dab97bb6ea1d4707d4245cf29b452e99
SHA-256: 7cb5bf1983db6fb90bf42202cab6dd5648e876ac365f32f96df1f1659d8fe479
Size: 294.87 kB - libpng-devel-1.6.37-15.el9_8.2.x86_64.rpm
MD5: c6292b3e09455faa54986d31f1f2c51e
SHA-256: 7c874a1d9f29a10c4610fda9ef9df93fb890da180e866e744268ce5743b09457
Size: 293.79 kB