UbuntuUpdates.org

Package "libpng-tools"

Name: libpng-tools

Description:

PNG library - tools (version 1.6)

Latest version: 1.6.37-3ubuntu0.7
Release: jammy (22.04)
Level: security
Repository: main
Head package: libpng1.6
Homepage: http://libpng.org/pub/png/libpng.html

Links


Download "libpng-tools"


Other versions of "libpng-tools" in Jammy

Repository Area Version
base main 1.6.37-3build5
updates main 1.6.37-3ubuntu0.6

Changelog

Version: 1.6.37-3ubuntu0.7 2026-10-08 03:07:21 UTC

libpng1.6 (1.6.37-3ubuntu0.7) jammy-security; urgency=medium

  * SECURITY UPDATE: Use-after-free in png_read_end
    - debian/patches/CVE-2026-46675.patch: Clear stale zstream pointers when
      releasing the inflate stream in pngrutil.c
    - CVE-2026-46675

 -- Kyle Kernick Mon, 05 Oct 2026 15:37:39 -0600

Source diff to previous version
CVE-2026-46675 Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt or iCCP decompression

Version: 1.6.37-3ubuntu0.6 2026-08-17 18:08:27 UTC
No changelog available yet.
Source diff to previous version

Version: 1.6.37-3ubuntu0.5 2026-05-07 14:07:30 UTC

  libpng1.6 (1.6.37-3ubuntu0.5) jammy-security; urgency=medium

  * SECURITY UPDATE: use-after-free via shared buffers
    - debian/patches/CVE-2026-33416-pre1.patch: Fix a memory leak in
      png_set_tRNS in pngset.c.
    - debian/patches/CVE-2026-33416-pre2.patch: Avoid a memory leak when
      allocation of a pCAL buffer fails in pngset.c.
    - debian/patches/CVE-2026-33416-1.patch: fix: Resolve use-after-free on
      `png_ptr->trans_alpha` in pngread.c, pngrutil.c, pngset.c, pngwrite.c.
    - debian/patches/CVE-2026-33416-2.patch: fix: Resolve use-after-free on
      `png_ptr->palette` in pngread.c, pngrtran.c, pngrutil.c, pngset.c,
      pngwrite.c.
    - debian/patches/CVE-2026-33416-3.patch: fix: Initialize tail bytes in
      `trans_alpha` buffers in pngset.c.
    - debian/patches/CVE-2026-33416-4.patch: fix: Sync `info_ptr->palette` after
      in-place transforms in pngrtran.c.
    - debian/patches/CVE-2026-33416-5.patch: fix: Sync `info_ptr->palette`
      unconditionally after in-place transforms in pngrtran.c.
    - CVE-2026-33416
  * SECURITY UPDATE: out-of-bounds access in ARM palette expansion path
    - debian/patches/CVE-2026-33636.patch: fix(arm): Resolve out-of-bounds
      read/write in NEON palette expansion in arm/palette_neon_intrinsics.c.
    - CVE-2026-33636
  * SECURITY UPDATE: getter-to-setter aliasing issues
    - debian/patches/CVE-2026-34757-1.patch: fix: Handle self-referencing
      pointers in getter-to-setter aliasing in CMakeLists.txt, Makefile.am,
      contrib/libtests/pnggetset.c, pngset.c, tests/pnggetset.
    - debian/patches/CVE-2026-34757-2.patch: fix: Handle getter-to-setter
      aliasing in append-style chunk setters in contrib/libtests/pnggetset.c,
      pngset.c.
    - debian/rules: set exec permissions on tests/pnggetset.
    - CVE-2026-34757
  * SECURITY UPDATE: integer overflow in rowbytes computation
    - debian/patches/rowbytes_overflow.patch: fix: Prevent integer overflow in
      rowbytes computation in pngrtran.c.
    - No CVE number

 -- Marc Deslauriers <email address hidden> Tue, 05 May 2026 15:14:16 -0400

Source diff to previous version
CVE-2026-33416 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versio
CVE-2026-33636 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versio
CVE-2026-34757 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.

Version: 1.6.37-3ubuntu0.4 2026-02-12 23:07:52 UTC

  libpng1.6 (1.6.37-3ubuntu0.4) jammy-security; urgency=medium

  * SECURITY UPDATE: OOB read in png_set_quantize()
    - debian/patches/CVE-2026-25646.patch: fix a heap buffer overflow in
      pngrtran.c.
    - CVE-2026-25646

 -- Marc Deslauriers <email address hidden> Wed, 11 Feb 2026 09:27:33 -0500

Source diff to previous version
CVE-2026-25646 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to

Version: 1.6.37-3ubuntu0.3 2026-01-14 18:07:38 UTC

  libpng1.6 (1.6.37-3ubuntu0.3) jammy-security; urgency=medium

  * SECURITY UPDATE: OOB in png_image_read_composite
    - debian/patches/CVE-2025-66293-1.patch: validate component size in
      pngread.c.
    - debian/patches/CVE-2025-66293-2.patch: improve fix in pngread.c.
    - CVE-2025-66293
  * SECURITY UPDATE: Heap buffer over-read in png_image_read_direct_scaled
    - debian/patches/CVE-2026-22695.patch: fix memcpy size in pngread.c.
    - CVE-2026-22695
  * SECURITY UPDATE: Integer truncation causing heap buffer over-read
    - debian/patches/CVE-2026-22801.patch: remove incorrect truncation
      casts in CMakeLists.txt, contrib/libtests/pngstest.c, pngwrite.c,
      tests/pngstest-large-stride.
    - CVE-2026-22801

 -- Marc Deslauriers <email address hidden> Mon, 12 Jan 2026 13:14:59 -0500

CVE-2025-66293 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to
CVE-2026-22695 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.
CVE-2026-22801 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.



About   -   Send Feedback to @ubuntu_updates