Heap-based buffer overflow in libpng - CVE-2025-65018
Published: November 26, 2025 / Updated: January 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the png_image_finish_read() function when processing 16-bit interlaced PNGs with 8-bit output format. A remote attacker can pass a specially crafted image file to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 15 SP4
Gentoo Linux
SUSE Linux Enterprise Server 15 SP5
Debian Linux
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.3
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Enterprise Storage
OpenBSD
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Anolis OS
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Google Android
Basesystem Module
openSUSE Leap
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
openEuler
Engineering Lifecycle Management
MySQL Workbench
Gitlab Community Edition
GitLab Enterprise Edition
Netezza Appliance
IBM Observability with Instana
Infrastructure Technology
Red Hat build of Keycloak
Communications Unified Assurance
LANTIME Operating System Firmware (LTOS)
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
libpng16-debugsource
libpng16-compat-devel
libpng16-16
libpng16-16-debuginfo
libpng16-devel
libpng16-16-32bit
libpng16-16-debuginfo-32bit
libpng1.6 (Ubuntu package)
mingw32-libpng
mingw64-libpng
mingw-libpng (Red Hat package)
libpng (Red Hat package)
libpng
libpng-devel
libpng-static
libpng16-16-32bit-debuginfo
libpng1.6 (Debian package)
libpng-debuginfo
libpng-debugsource
libpng-help
libpng-tools
libpng-doc
libpng16-16-64bit-debuginfo
libpng16-16-64bit
libpng16-tools-debuginfo
libpng16-tools
libpng16-compat-devel-32bit
libpng16-devel-32bit
libpng16-compat-devel-64bit
libpng16-devel-64bit
libpng16-16-x86-64-v3-debuginfo
libpng16-devel-x86-64-v3
libpng16-16-x86-64-v3
libpng16-compat-devel-x86-64-v3
media-libs/libpng
java-1.8.0-openjdk-src
java-1.8.0-openjdk-javadoc
java-1.8.0-openjdk-javadoc-zip
java-1.8.0-openjdk
java-1.8.0-openjdk-accessibility
java-1.8.0-openjdk-demo
java-1.8.0-openjdk-devel
java-1.8.0-openjdk-headless
java-17-openjdk-static-libs
java-17-openjdk-src
java-17-openjdk-jmods
java-17-openjdk-javadoc-zip
java-17-openjdk-javadoc
java-17-openjdk-headless
java-17-openjdk-devel
java-17-openjdk-demo
java-17-openjdk
java-17-openjdk (Red Hat package)
java-21-openjdk-static-libs
java-21-openjdk-src
java-21-openjdk-jmods
java-21-openjdk-javadoc-zip
java-21-openjdk-javadoc
java-21-openjdk-headless
java-21-openjdk-devel
java-21-openjdk-demo
java-21-openjdk
OpenShift Virtualization
IBM Qradar SIEM
Juniper Junos Space
How to mitigate CVE-2025-65018
Engineering Lifecycle Management - update to 1.3.0
Netezza Appliance - update to 1.0.1.0 fp278500
IBM Observability with Instana - update to 1.0.313
LANTIME Operating System Firmware (LTOS) - update to 7.10.008
Juniper Secure Analytics (JSA) - update to 7.5.0 UP15 IF01
Google Android - addressed in versions 14 2026-06-01, 15 2026-06-01, 16-qpr2 2026-06-01, 16 2026-06-01
Gitlab Community Edition - addressed in versions 18.5.5, 18.6.3, 18.7.1
GitLab Enterprise Edition - addressed in versions 18.5.5, 18.6.3, 18.7.1
libpng16-debugsource - addressed in versions 1.6.8-15.9.1, 1.6.34-150000.3.12.1, 1.6.40-150600.3.3.1, 1.6.44-160000.3.1
libpng16-compat-devel - addressed in versions 1.6.8-15.9.1, 1.6.34-150000.3.12.1, 1.6.40-150600.3.3.1, 1.6.44-160000.3.1
libpng16-16 - addressed in versions 1.6.8-15.9.1, 1.6.34-150000.3.12.1, 1.6.40-150600.3.3.1, 1.6.44-160000.3.1
libpng16-16-debuginfo - addressed in versions 1.6.8-15.9.1, 1.6.34-150000.3.12.1, 1.6.40-150600.3.3.1, 1.6.44-160000.3.1
libpng16-devel - addressed in versions 1.6.8-15.9.1, 1.6.34-150000.3.12.1, 1.6.40-150600.3.3.1, 1.6.44-160000.3.1
libpng16-16-32bit - addressed in versions 1.6.8-15.9.1, 1.6.34-150000.3.12.1, 1.6.40-150600.3.3.1
libpng16-16-debuginfo-32bit - update to 1.6.8-15.9.1
libpng1.6 (Ubuntu package) - addressed in versions 1.6.20-2ubuntu0.1~esm2, 1.6.34-1ubuntu0.18.04.2+esm1, 1.6.37-2ubuntu0.1~esm1, 1.6.37-3ubuntu0.1, 1.6.43-5ubuntu0.1, 1.6.47-1.1ubuntu0.1, 1.6.50-1ubuntu0.1
mingw32-libpng - addressed in versions 1.6.34-1, 1.6.34-2
mingw64-libpng - addressed in versions 1.6.34-1, 1.6.34-2
mingw-libpng (Red Hat package) - update to 1.6.34-1.el8_10
libpng (Red Hat package) - addressed in versions 1.6.34-8.el8_2.1, 1.6.34-8.el8_4.1, 1.6.34-8.el8_6.1, 1.6.34-8.el8_8.1, 1.6.34-9.el8_10, 1.6.37-12.el9_0.1, 1.6.37-12.el9_2.1, 1.6.37-12.el9_7.1, 1.6.40-8.el10_0.1, 1.6.40-8.el10_1.1
libpng - addressed in versions 1.6.34-9, 1.6.34-10, 1.6.40-2
libpng-devel - addressed in versions 1.6.34-9, 1.6.34-10, 1.6.40-2
libpng-static - addressed in versions 1.6.34-10, 1.6.40-2
libpng16-16-32bit-debuginfo - addressed in versions 1.6.34-150000.3.12.1, 1.6.40-150600.3.3.1
libpng1.6 (Debian package) - addressed in versions 1.6.39-2+deb12u1, 1.6.48-1+deb13u1
libpng - addressed in versions 1.6.40-2, 1.6.40-5
libpng-debuginfo - addressed in versions 1.6.40-2, 1.6.40-5
libpng-debugsource - addressed in versions 1.6.40-2, 1.6.40-5
libpng-devel - addressed in versions 1.6.40-2, 1.6.40-5
libpng-help - addressed in versions 1.6.40-2, 1.6.40-5
libpng-static - addressed in versions 1.6.40-2, 1.6.40-5
libpng-tools - addressed in versions 1.6.40-2, 1.6.40-5
libpng-doc - update to 1.6.40-2
libpng-tools - update to 1.6.40-2
libpng16-16-64bit-debuginfo - update to 1.6.40-150600.3.3.1
libpng16-16-64bit - update to 1.6.40-150600.3.3.1
libpng16-tools-debuginfo - addressed in versions 1.6.40-150600.3.3.1, 1.6.44-160000.3.1
libpng16-tools - addressed in versions 1.6.40-150600.3.3.1, 1.6.44-160000.3.1
libpng16-compat-devel-32bit - update to 1.6.40-150600.3.3.1
libpng16-devel-32bit - update to 1.6.40-150600.3.3.1
libpng16-compat-devel-64bit - update to 1.6.40-150600.3.3.1
libpng16-devel-64bit - update to 1.6.40-150600.3.3.1
libpng16-16-x86-64-v3-debuginfo - update to 1.6.44-160000.3.1
libpng16-devel-x86-64-v3 - update to 1.6.44-160000.3.1
libpng16-16-x86-64-v3 - update to 1.6.44-160000.3.1
libpng16-compat-devel-x86-64-v3 - update to 1.6.44-160000.3.1
media-libs/libpng - update to 1.6.51
java-1.8.0-openjdk-src - addressed in versions 1.8.0.472.b08-3, 1.8.0.482.b08-1.0.1
java-1.8.0-openjdk-javadoc - addressed in versions 1.8.0.472.b08-3, 1.8.0.482.b08-1.0.1
java-1.8.0-openjdk-javadoc-zip - addressed in versions 1.8.0.472.b08-3, 1.8.0.482.b08-1.0.1
java-1.8.0-openjdk - addressed in versions 1.8.0.472.b08-3, 1.8.0.482.b08-1.0.1
java-1.8.0-openjdk-accessibility - addressed in versions 1.8.0.472.b08-3, 1.8.0.482.b08-1.0.1
java-1.8.0-openjdk-demo - addressed in versions 1.8.0.472.b08-3, 1.8.0.482.b08-1.0.1
java-1.8.0-openjdk-devel - addressed in versions 1.8.0.472.b08-3, 1.8.0.482.b08-1.0.1
java-1.8.0-openjdk-headless - addressed in versions 1.8.0.472.b08-3, 1.8.0.482.b08-1.0.1
OpenShift Virtualization - update to 4.19.17
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF04
java-17-openjdk-static-libs - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk-src - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk-jmods - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk-javadoc-zip - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk-javadoc - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk-headless - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk-devel - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk-demo - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk - addressed in versions 17.0.17.0.10-3, 17.0.18.0.8-1.0.2
java-17-openjdk (Red Hat package) - addressed in versions 17.0.18.0.8-1.el8, 17.0.18.0.8-1.el9
java-21-openjdk-static-libs - update to 21.0.10.0.7-1.0.2
java-21-openjdk-src - update to 21.0.10.0.7-1.0.2
java-21-openjdk-jmods - update to 21.0.10.0.7-1.0.2
java-21-openjdk-javadoc-zip - update to 21.0.10.0.7-1.0.2
java-21-openjdk-javadoc - update to 21.0.10.0.7-1.0.2
java-21-openjdk-headless - update to 21.0.10.0.7-1.0.2
java-21-openjdk-devel - update to 21.0.10.0.7-1.0.2
java-21-openjdk-demo - update to 21.0.10.0.7-1.0.2
java-21-openjdk - update to 21.0.10.0.7-1.0.2
Juniper Junos Space - update to 26.1R1 Patch V1
Red Hat build of Keycloak - update to 26.2.13
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Multiple vulnerabilities in libpng
- Gentoo update for libpng
- openEuler update for libpng
- OpenBSD update for libpng
- Anolis OS update for libpng
- Debian update for libpng1.6
- Ubuntu update for libpng1.6
- SUSE update for libpng16
- SUSE update for libpng16
- SUSE update for libpng16
- Red Hat Enterprise Linux 8 update for mingw-libpng
- Red Hat Enterprise Linux 10 update for libpng
- Red Hat Enterprise Linux 9 update for libpng
- Red Hat Enterprise Linux 9 update for libpng
- Red Hat Enterprise Linux 10 update for libpng
- Red Hat Enterprise Linux 9 update for libpng
- Red Hat Enterprise Linux 8 update for libpng
- GitLab CE/EE update for Libpng
- Red Hat Enterprise Linux 8 update for libpng
- Red Hat Enterprise Linux 8 update for libpng
- Red Hat Enterprise Linux 8 update for libpng
- Red Hat Enterprise Linux 8 update for libpng
- Anolis OS update for mingw-libpng
- Anolis OS update for libpng
- SUSE update for libpng16
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in MySQL Workbench
- Multiple vulnerabilities in OpenShift Virtualization 4.19
- Red Hat Enterprise Linux 9 update for java-17-openjdk
- openEuler update for libpng
- Multiple vulnerabilities in IBM QRadar SIEM
- Anolis OS update for java-1.8.0-openjdk
- Anolis OS update for java-21-openjdk
- Anolis OS update for java-17-openjdk
- Multiple vulnerabilities in Red Hat build of Keycloak 26.2
- Meinberg LANTIME firmware update for third-party components
- Multiple vulnerabilities in IBM Observability with Instana
- Multiple vulnerabilities in IBM Engineering Lifecycle Management on Hybrid Cloud
- Anolis OS update for mingw-libpng
- Anolis OS update for libpng
- Anolis OS update for java-17-openjdk
- Anolis OS update for java-1.8.0-openjdk
- Multiple vulnerabilities in IBM Netezza Appliance
- Multiple vulnerabilities in Infrastructure Technology
- Multiple vulnerabilities in Juniper Secure Analytics
- Multiple vulnerabilities in Google Android
- Multiple vulnerabilities in Junos Space