Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0237 - Security Advisory
Issued:
2026-01-07
Updated:
2026-01-07

RHSA-2026:0237 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libpng security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libpng is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.

Security Fix(es):

  • libpng: LIBPNG buffer overflow (CVE-2025-64720)
  • libpng: LIBPNG heap buffer overflow (CVE-2025-65018)
  • libpng: LIBPNG out-of-bounds read in png_image_read_composite (CVE-2025-66293)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2416904 - CVE-2025-64720 libpng: LIBPNG buffer overflow
  • BZ - 2416907 - CVE-2025-65018 libpng: LIBPNG heap buffer overflow
  • BZ - 2418711 - CVE-2025-66293 libpng: LIBPNG out-of-bounds read in png_image_read_composite

CVEs

  • CVE-2025-64720
  • CVE-2025-65018
  • CVE-2025-66293

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
libpng-1.6.40-8.el10_1.1.src.rpm SHA-256: 73a51a1325eff1ea350a37f16a7002325909b96d46366efd391d52b9c1d00778
x86_64
libpng-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: 911a2b1a5578fb7f52d46c202341358a3a7815402310f3a8309757e16ab22ec2
libpng-debuginfo-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: e3ccefb2cace8bd7396b1c374d441326c0e7b40cb6b013d1ae447fef64e6e708
libpng-debuginfo-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: e3ccefb2cace8bd7396b1c374d441326c0e7b40cb6b013d1ae447fef64e6e708
libpng-debugsource-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: 256a2f8f16bb80a4a21ae73ae57b65414f03b431df71c1a9cc168a5094bb8477
libpng-debugsource-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: 256a2f8f16bb80a4a21ae73ae57b65414f03b431df71c1a9cc168a5094bb8477
libpng-devel-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: 59772e1566ccca21fa02627117dcf1b9729ea4b34f6fb22ce711ce1c506228ee
libpng-devel-debuginfo-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: ac93ee1935b99f4f298641b4df9549d9e2789cd54f535d5e2d7f4a7232012522
libpng-devel-debuginfo-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: ac93ee1935b99f4f298641b4df9549d9e2789cd54f535d5e2d7f4a7232012522
libpng-tools-debuginfo-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: 65cfafe216892aa623db58c44f2f905dfd8cd9d526562df4f7f78481dba7ba29
libpng-tools-debuginfo-1.6.40-8.el10_1.1.x86_64.rpm SHA-256: 65cfafe216892aa623db58c44f2f905dfd8cd9d526562df4f7f78481dba7ba29

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
s390x
libpng-1.6.40-8.el10_1.1.s390x.rpm SHA-256: be9fd827a5a1dd3cb56e7e435aa18db679fc46614ccd2bb98ba0762ccda1cc3f
libpng-debuginfo-1.6.40-8.el10_1.1.s390x.rpm SHA-256: 95871b2f7447ad209ee057577788b38b58f97aa0a5b02f97c5cb178d094b9f6a
libpng-debugsource-1.6.40-8.el10_1.1.s390x.rpm SHA-256: f7fc0caff09b3dc35a6b76ab9e452d15b48cd15e24094c9f96a2cc656963be05
libpng-devel-1.6.40-8.el10_1.1.s390x.rpm SHA-256: 2954ea53047cc08ff23320b6c1006dc1a4fcb56e61a6d44312c621d5eeb32dda
libpng-devel-debuginfo-1.6.40-8.el10_1.1.s390x.rpm SHA-256: c04becdb4ee8c12e966af330b27e64416278f68712542f2b25429fd69c768acb
libpng-tools-debuginfo-1.6.40-8.el10_1.1.s390x.rpm SHA-256: c30200107294e171c6a977afed828a057ca971f97e691810f24c43036979aeef

Red Hat Enterprise Linux for Power, little endian 10

SRPM
libpng-1.6.40-8.el10_1.1.src.rpm SHA-256: 73a51a1325eff1ea350a37f16a7002325909b96d46366efd391d52b9c1d00778
ppc64le
libpng-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: 851992e51c74d5f8e6598494027ca9776d93302b9470306b9e4154223844219c
libpng-debuginfo-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: 454b223e2d627e6d595ab77fd6a70c2ef06c6d881969c94347b60a0ad900d2cf
libpng-debuginfo-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: 454b223e2d627e6d595ab77fd6a70c2ef06c6d881969c94347b60a0ad900d2cf
libpng-debugsource-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: b3ed6853e55d29c5648b43b9fe5e00eb32cbbc1b8f3e2f3c498ac17152b21e92
libpng-debugsource-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: b3ed6853e55d29c5648b43b9fe5e00eb32cbbc1b8f3e2f3c498ac17152b21e92
libpng-devel-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: dd8e4356323cd50489e27c23ed38c097c38b2dc68fd42e1d6846370f3625884d
libpng-devel-debuginfo-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: cfc23d0d45eac6927aff2c630d4269a9515236289477677bb8cc900b03bc8a94
libpng-devel-debuginfo-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: cfc23d0d45eac6927aff2c630d4269a9515236289477677bb8cc900b03bc8a94
libpng-tools-debuginfo-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: 657630de74ba4648b934d7046091e3d0cc163dd88b6f53e94f8748e9d93e0865
libpng-tools-debuginfo-1.6.40-8.el10_1.1.ppc64le.rpm SHA-256: 657630de74ba4648b934d7046091e3d0cc163dd88b6f53e94f8748e9d93e0865

Red Hat Enterprise Linux for ARM 64 10

SRPM
libpng-1.6.40-8.el10_1.1.src.rpm SHA-256: 73a51a1325eff1ea350a37f16a7002325909b96d46366efd391d52b9c1d00778
aarch64
libpng-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: 536012dd46e338d1c3e8b359eee1915610ba92af9807e5e10ccc842afbfedcd5
libpng-debuginfo-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: 7210d61323b4f3435bc1f06ab10ce37a737b2c8502ad87831d4ebbc574296c18
libpng-debuginfo-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: 7210d61323b4f3435bc1f06ab10ce37a737b2c8502ad87831d4ebbc574296c18
libpng-debugsource-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: bad69bd8dc19febdcfc0be3ab5265b267eebcf3d75de248097da820113aa693b
libpng-debugsource-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: bad69bd8dc19febdcfc0be3ab5265b267eebcf3d75de248097da820113aa693b
libpng-devel-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: 8e5489ca1cd011b58332834ee472fc678427da95bdb830cd486bea07f7da1219
libpng-devel-debuginfo-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: b27bc55776001a1e47c8f8e736fa47d888bc54a859d766fcc6a47a150ec98da9
libpng-devel-debuginfo-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: b27bc55776001a1e47c8f8e736fa47d888bc54a859d766fcc6a47a150ec98da9
libpng-tools-debuginfo-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: d1c79e5d0ce1045910a5d49a80f33fb9e2b4ff79290b596bd0f7d948d799d98b
libpng-tools-debuginfo-1.6.40-8.el10_1.1.aarch64.rpm SHA-256: d1c79e5d0ce1045910a5d49a80f33fb9e2b4ff79290b596bd0f7d948d799d98b

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility