Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0234 - Security Advisory
Issued:
2026-01-07
Updated:
2026-01-07

RHSA-2026:0234 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libpng security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libpng is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.

Security Fix(es):

  • libpng: LIBPNG buffer overflow (CVE-2025-64720)
  • libpng: LIBPNG heap buffer overflow (CVE-2025-65018)
  • libpng: LIBPNG out-of-bounds read in png_image_read_composite (CVE-2025-66293)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2416904 - CVE-2025-64720 libpng: LIBPNG buffer overflow
  • BZ - 2416907 - CVE-2025-65018 libpng: LIBPNG heap buffer overflow
  • BZ - 2418711 - CVE-2025-66293 libpng: LIBPNG out-of-bounds read in png_image_read_composite

CVEs

  • CVE-2025-64720
  • CVE-2025-65018
  • CVE-2025-66293

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
libpng-1.6.37-12.el9_0.1.src.rpm SHA-256: 6667f25696d8b159ef030466ad52c144f76fb529c3d4dd91dd498f3e311fe659
ppc64le
libpng-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: 9d1e23d2b187750e49ffcc14f69829f4edb73a7ac786d7ce4377186d4b9a8267
libpng-debuginfo-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: 349b2c95653e192ae423e1e7385164c087e3dc7d14a2ed10a168f6c1cb30b097
libpng-debuginfo-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: 349b2c95653e192ae423e1e7385164c087e3dc7d14a2ed10a168f6c1cb30b097
libpng-debugsource-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: 162dda83b5d3e61f9ef2bed30075a621b4f579e0796140bb509d344931d94246
libpng-debugsource-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: 162dda83b5d3e61f9ef2bed30075a621b4f579e0796140bb509d344931d94246
libpng-devel-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: 4a26cdb7f4bdeaee320cf2900befae439950c1a5543208ce657a33e97bf3ea0b
libpng-devel-debuginfo-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: d5aa7d6b009ca818423b1010b00f8b3367471f0739a2d063473a084fc716207f
libpng-devel-debuginfo-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: d5aa7d6b009ca818423b1010b00f8b3367471f0739a2d063473a084fc716207f
libpng-tools-debuginfo-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: 3a9e8da150dc53e364e90fdaa91fab5fe7515990628612a0627100d17325ebec
libpng-tools-debuginfo-1.6.37-12.el9_0.1.ppc64le.rpm SHA-256: 3a9e8da150dc53e364e90fdaa91fab5fe7515990628612a0627100d17325ebec

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
libpng-1.6.37-12.el9_0.1.src.rpm SHA-256: 6667f25696d8b159ef030466ad52c144f76fb529c3d4dd91dd498f3e311fe659
x86_64
libpng-1.6.37-12.el9_0.1.i686.rpm SHA-256: 10e990e67b854bea363777daa17104f4b128fe1c75843f0b54d14b0975488515
libpng-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: e6e1ee9c544ea17ee2b118baba98781520c284dd36d416e17af7585058a6f94c
libpng-debuginfo-1.6.37-12.el9_0.1.i686.rpm SHA-256: bdad53ab6bd6882cef571d4efbeb74f34987bfe537c7cfff6102f5001736444d
libpng-debuginfo-1.6.37-12.el9_0.1.i686.rpm SHA-256: bdad53ab6bd6882cef571d4efbeb74f34987bfe537c7cfff6102f5001736444d
libpng-debuginfo-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: cd1a485a185b7315ff0a86815d01be7e09211c7754e67c3e916f31f36c24f8fe
libpng-debuginfo-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: cd1a485a185b7315ff0a86815d01be7e09211c7754e67c3e916f31f36c24f8fe
libpng-debugsource-1.6.37-12.el9_0.1.i686.rpm SHA-256: 04382299af9ffbcf83723bd4ae56e2fba84af05d00884e785ac8af19fd007819
libpng-debugsource-1.6.37-12.el9_0.1.i686.rpm SHA-256: 04382299af9ffbcf83723bd4ae56e2fba84af05d00884e785ac8af19fd007819
libpng-debugsource-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: ae1ad56c34d101ad7c217eba923b3bc3b5c8baaeae71560b8e9428b3cb0ca309
libpng-debugsource-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: ae1ad56c34d101ad7c217eba923b3bc3b5c8baaeae71560b8e9428b3cb0ca309
libpng-devel-1.6.37-12.el9_0.1.i686.rpm SHA-256: c3a99aa66bc11b3b2e35b4ec32147c7a3e174b2166c94437c0bb3ad759750b71
libpng-devel-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: 3553c0a3fe92f54ee25386bf3104487b1d118e67e98e08e659e4ecbc682d61a1
libpng-devel-debuginfo-1.6.37-12.el9_0.1.i686.rpm SHA-256: 6e381e956ab89c17bf102c9d32900128cbde3127b2cf1c786284bd99ce888548
libpng-devel-debuginfo-1.6.37-12.el9_0.1.i686.rpm SHA-256: 6e381e956ab89c17bf102c9d32900128cbde3127b2cf1c786284bd99ce888548
libpng-devel-debuginfo-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: b259fd6eca56f796fd7706e22f0d57f7e34b8427be6045b838396a80da567bc2
libpng-devel-debuginfo-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: b259fd6eca56f796fd7706e22f0d57f7e34b8427be6045b838396a80da567bc2
libpng-tools-debuginfo-1.6.37-12.el9_0.1.i686.rpm SHA-256: 81a70b75da999f5f64dd64fa2237741bc228c194ac083761940f6fc9195749c5
libpng-tools-debuginfo-1.6.37-12.el9_0.1.i686.rpm SHA-256: 81a70b75da999f5f64dd64fa2237741bc228c194ac083761940f6fc9195749c5
libpng-tools-debuginfo-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: 29f63c7a90a660623b894a05a228020839d9b05836979e49e36af59372ee96ce
libpng-tools-debuginfo-1.6.37-12.el9_0.1.x86_64.rpm SHA-256: 29f63c7a90a660623b894a05a228020839d9b05836979e49e36af59372ee96ce

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
libpng-1.6.37-12.el9_0.1.src.rpm SHA-256: 6667f25696d8b159ef030466ad52c144f76fb529c3d4dd91dd498f3e311fe659
aarch64
libpng-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: 2831a09c746ee939f7645aeeb14d8b8973e8ba041ced3461fa9bbc6a971d2d52
libpng-debuginfo-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: 594a42e298afa33c2097dcea7eb723632a2e6dfb029b3fdac54579aef5f47a8e
libpng-debuginfo-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: 594a42e298afa33c2097dcea7eb723632a2e6dfb029b3fdac54579aef5f47a8e
libpng-debugsource-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: 44f075c868d8f37695dfe3ca49a16ae7aa3a3518fcda0c59cd387e82b8865c1d
libpng-debugsource-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: 44f075c868d8f37695dfe3ca49a16ae7aa3a3518fcda0c59cd387e82b8865c1d
libpng-devel-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: d175c6683948a5f769adaad3f7b2591f018c127c78827d8fca12342777f507da
libpng-devel-debuginfo-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: 46ffbe511fbe2a4e09061cea5c241a5564d81839e0f52f9fe3b6c6d2561d475f
libpng-devel-debuginfo-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: 46ffbe511fbe2a4e09061cea5c241a5564d81839e0f52f9fe3b6c6d2561d475f
libpng-tools-debuginfo-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: a68fff01f6e8a1cd247145423f3d01de62f8013baa9724b47b006cfecfaa7610
libpng-tools-debuginfo-1.6.37-12.el9_0.1.aarch64.rpm SHA-256: a68fff01f6e8a1cd247145423f3d01de62f8013baa9724b47b006cfecfaa7610

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
s390x
libpng-1.6.37-12.el9_0.1.s390x.rpm SHA-256: 23eeb60c0f13ab0af233f7e344c742b2626c6789cbe1b8a84829d4656e65d123
libpng-debuginfo-1.6.37-12.el9_0.1.s390x.rpm SHA-256: 76b5a1c33bad8ef823bad3459090504741fb6701a07b016a11610522d85e46ca
libpng-debugsource-1.6.37-12.el9_0.1.s390x.rpm SHA-256: 4132e52705f8b852f65bc40c750e240fb9636677e07d3c4e4ad7033686b246d7
libpng-devel-1.6.37-12.el9_0.1.s390x.rpm SHA-256: ab88742e75d5a494731766de264b9cd2d45a0fd4fbd2c1473a2b6f12aa637e56
libpng-devel-debuginfo-1.6.37-12.el9_0.1.s390x.rpm SHA-256: e6c4f6f44f3b643b7d34d2df7840c77a16a083621af15c39f8f6ea50a2fdf5cc
libpng-tools-debuginfo-1.6.37-12.el9_0.1.s390x.rpm SHA-256: 087f13787421cccbfd196ff2a0774bfafd32ec33828d59fb9f25e0790c7acef9

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility