Known vulnerabilities in libpng (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:libpng_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 9
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting libpng (Red Hat package) libpng (Red Hat package) is affected by 9 known vulnerabilities: 1 critical, 2 high, 5 medium, 1 low Critical High Medium Low

Vulnerabilities (9)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU125601 - Use After Free
CVE-2026-33416
CWE-416 High
No
No
1.6.34-8.el8_4.3, 1.6.34-8.el8_6.3, 1.6.34-8.el8_8.3, 1.6.37-12.el9_7.4 09.04.2026 SB2026040959
SB2026040962
SB2026040963
and 56 more
#VU125600 - Out-of-bounds read
CVE-2026-33636
CWE-125 Medium
No
No
1.6.37-12.el9_0.3, 1.6.37-12.el9_2.3, 1.6.37-12.el9_4.3, 1.6.37-12.el9_6.3, 1.6.37-12.el9_7.3, 1.6.40-8.el10_0.3, 1.6.40-8.el10_1.3 09.04.2026 SB2026040959
SB2026040962
SB2026040963
and 43 more
#VU122489 - Heap-based Buffer Overflow
CVE-2026-25646
CWE-122 High
No
No
1.6.34-8.el8_2.2, 1.6.34-8.el8_4.2, 1.6.34-8.el8_8.2, 1.6.34-10.el8_10, 1.6.37-12.el9_0.2, 1.6.37-12.el9_2.2, 1.6.37-12.el9_7.2, 1.6.40-8.el10_0.2, 1.6.40-8.el10_1.2 10.02.2026 SB2026021002
SB2026021255
SB2026021256
and 62 more
#VU121184 - Out-of-bounds read
CVE-2026-22801
CWE-125 Medium
No
No
1.6.34-8.el8_2.2, 1.6.34-8.el8_4.2, 1.6.34-8.el8_8.2, 1.6.34-10.el8_10, 1.6.37-12.el9_0.2, 1.6.37-12.el9_2.2, 1.6.37-12.el9_7.2, 1.6.40-8.el10_0.2, 1.6.40-8.el10_1.2 13.01.2026 SB2026011311
SB20260114154
SB2026012271
and 22 more
#VU121183 - Out-of-bounds read
CVE-2026-22695
CWE-125 Medium
No
No
1.6.34-8.el8_2.2, 1.6.34-8.el8_4.2, 1.6.34-8.el8_8.2, 1.6.34-10.el8_10, 1.6.37-12.el9_0.2, 1.6.37-12.el9_2.2, 1.6.37-12.el9_7.2, 1.6.40-8.el10_0.2, 1.6.40-8.el10_1.2 13.01.2026 SB2026011311
SB20260114154
SB2026012137
and 22 more
#VU119115 - Out-of-bounds read
CVE-2025-66293
CWE-125 Medium
No
No
1.6.34-8.el8_2.1, 1.6.34-8.el8_4.1, 1.6.34-8.el8_6.1, 1.6.34-8.el8_8.1, 1.6.34-9.el8_10, 1.6.37-12.el9_0.1, 1.6.37-12.el9_2.1, 1.6.37-12.el9_7.1, 1.6.40-8.el10_0.1, 1.6.40-8.el10_1.1 03.12.2025 SB2025120348
SB20251210187
SB2025121761
and 40 more
#VU118778 - Out-of-bounds read
CVE-2025-64720
CWE-125 Medium
No
No
1.5.13-8.el7_9.1, 1.6.34-8.el8_2.1, 1.6.34-8.el8_4.1, 1.6.34-8.el8_6.1, 1.6.34-8.el8_8.1, 1.6.34-9.el8_10, 1.6.37-12.el9_0.1, 1.6.37-12.el9_2.1, 1.6.37-12.el9_7.1, 1.6.40-8.el10_0.1, 1.6.40-8.el10_1.1 26.11.2025 SB2025112638
SB2025112639
SB2025112819
and 39 more
#VU118777 - Heap-based Buffer Overflow
CVE-2025-65018
CWE-122 Critical
Available
No
1.6.34-8.el8_2.1, 1.6.34-8.el8_4.1, 1.6.34-8.el8_6.1, 1.6.34-8.el8_8.1, 1.6.34-9.el8_10, 1.6.37-12.el9_0.1, 1.6.37-12.el9_2.1, 1.6.37-12.el9_7.1, 1.6.40-8.el10_0.1, 1.6.40-8.el10_1.1 26.11.2025 SB2025112638
SB2025112639
SB2025112819
and 44 more
#VU19180 - Improper input validation
CVE-2017-12652
CWE-20 Low
No
No
1.5.13-8.el7 15.07.2019 SB2019071033
SB2020020613
SB2020093077
and 16 more