SB2026020422 - Two memory leak vulnerabilities in libpng
Published: February 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Memory leak (CVE-ID: CVE-2025-28162)
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in png_malloc_base() function. A remote attacker can supply a specially crafted image file to the application and force the library to leak memory.
2) Memory leak (CVE-ID: CVE-2025-28164)
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in png_create_read_struct() function. A remote attacker can supply a specially crafted image file to the application and force the library to leak memory.
Remediation
Install update from vendor's website.