Use-after-free in libpng - CVE-2026-46675
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to use-after-free in the libpng sequential reader's png_read_end function when processing crafted zTXt, iTXt, or iCCP chunks after incomplete decompression. A remote attacker can provide a crafted PNG file to cause a denial of service.
Exploitation requires an application to call png_read_end after png_read_info without first reading image rows.
Affected software
Debian Linux
libpng1.6 (Debian package)
How to mitigate CVE-2026-46675
libpng1.6 (Debian package) - update to 1.6.48-1+deb13u6