Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:0313 - Security Advisory
Issued:
2026-01-08
Updated:
2026-01-08

RHSA-2026:0313 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libpng security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libpng is now available for Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions and Red Hat Enterprise Linux 8.8 Telecommunications Update Service.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.

Security Fix(es):

  • libpng: LIBPNG buffer overflow (CVE-2025-64720)
  • libpng: LIBPNG heap buffer overflow (CVE-2025-65018)
  • libpng: LIBPNG out-of-bounds read in png_image_read_composite (CVE-2025-66293)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64
  • Red Hat Enterprise Linux Server - TUS 8.8 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64

Fixes

  • BZ - 2416904 - CVE-2025-64720 libpng: LIBPNG buffer overflow
  • BZ - 2416907 - CVE-2025-65018 libpng: LIBPNG heap buffer overflow
  • BZ - 2418711 - CVE-2025-66293 libpng: LIBPNG out-of-bounds read in png_image_read_composite

CVEs

  • CVE-2025-64720
  • CVE-2025-65018
  • CVE-2025-66293

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8

SRPM
libpng-1.6.34-8.el8_8.1.src.rpm SHA-256: f2d41362de0e31f3a1d58e8b14c1707a3e2f966d6c9585b0c7afe8f83f7955b2
x86_64
libpng-1.6.34-8.el8_8.1.i686.rpm SHA-256: 7ab059fb75e2ea831c66544c94e6084bf449c58d030cd268e30f62b5132b62c8
libpng-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 5fde7bfe96fbe06a173144c5bf2e2cd2c3755eafd4a7b3eacc2e48b6c1848341
libpng-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: a0adaec849a4f1fce82da98e64255fe5a49414c0c71089f922b4744fe0fbb660
libpng-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 3ee6ed1db57cacfbbc7cbc2685be3843f4620e2dd73639f2825afc935c4a8eff
libpng-debugsource-1.6.34-8.el8_8.1.i686.rpm SHA-256: 21b319b6d842d20c770b4cdb2462568c4c8cc78b0bf4c56226d8915c6571b499
libpng-debugsource-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 344f99c02fc1fa51be1185eff505bbe6484e6627fc3f7598ec4b0571f8cd6f8e
libpng-devel-1.6.34-8.el8_8.1.i686.rpm SHA-256: 9209a7b57dbe5f5f538bc9721f35befb496c4ce2ec1b297f09321bc41997c384
libpng-devel-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 4d7ac27f1c095fcee5e3b044e2cfb7eec9688145bf6f8cc4bb59e9068180627e
libpng-devel-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: 9d46702eb1fdae27a940b627f51900e2cf095c81ce0db31dfa6eff1faa4f308d
libpng-devel-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 155c84d1fdf8dcfce7776ef44230b41b9d77c016d0e6efe5e3c708078e7e0a19
libpng-tools-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: dc089031aefbcbc93133bd6eec0fb8e4c49cc40f1ab377f5212063d9645ad8c1
libpng-tools-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 7de094ac9d2ebd051e02762947c8e528ad7b4e454be1823f662cff16e37f6838

Red Hat Enterprise Linux Server - TUS 8.8

SRPM
libpng-1.6.34-8.el8_8.1.src.rpm SHA-256: f2d41362de0e31f3a1d58e8b14c1707a3e2f966d6c9585b0c7afe8f83f7955b2
x86_64
libpng-1.6.34-8.el8_8.1.i686.rpm SHA-256: 7ab059fb75e2ea831c66544c94e6084bf449c58d030cd268e30f62b5132b62c8
libpng-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 5fde7bfe96fbe06a173144c5bf2e2cd2c3755eafd4a7b3eacc2e48b6c1848341
libpng-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: a0adaec849a4f1fce82da98e64255fe5a49414c0c71089f922b4744fe0fbb660
libpng-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 3ee6ed1db57cacfbbc7cbc2685be3843f4620e2dd73639f2825afc935c4a8eff
libpng-debugsource-1.6.34-8.el8_8.1.i686.rpm SHA-256: 21b319b6d842d20c770b4cdb2462568c4c8cc78b0bf4c56226d8915c6571b499
libpng-debugsource-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 344f99c02fc1fa51be1185eff505bbe6484e6627fc3f7598ec4b0571f8cd6f8e
libpng-devel-1.6.34-8.el8_8.1.i686.rpm SHA-256: 9209a7b57dbe5f5f538bc9721f35befb496c4ce2ec1b297f09321bc41997c384
libpng-devel-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 4d7ac27f1c095fcee5e3b044e2cfb7eec9688145bf6f8cc4bb59e9068180627e
libpng-devel-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: 9d46702eb1fdae27a940b627f51900e2cf095c81ce0db31dfa6eff1faa4f308d
libpng-devel-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 155c84d1fdf8dcfce7776ef44230b41b9d77c016d0e6efe5e3c708078e7e0a19
libpng-tools-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: dc089031aefbcbc93133bd6eec0fb8e4c49cc40f1ab377f5212063d9645ad8c1
libpng-tools-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 7de094ac9d2ebd051e02762947c8e528ad7b4e454be1823f662cff16e37f6838

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8

SRPM
libpng-1.6.34-8.el8_8.1.src.rpm SHA-256: f2d41362de0e31f3a1d58e8b14c1707a3e2f966d6c9585b0c7afe8f83f7955b2
ppc64le
libpng-1.6.34-8.el8_8.1.ppc64le.rpm SHA-256: 25879b1857bf7bc59e54a398510306186ce6cf3c70fd584a777f966d4d26942a
libpng-debuginfo-1.6.34-8.el8_8.1.ppc64le.rpm SHA-256: b1618a94979909bbd153fb6efc3297f891a178aa44734fab35c44931f53e6569
libpng-debugsource-1.6.34-8.el8_8.1.ppc64le.rpm SHA-256: 8ff821f9f40f660f64566e7f67fa18ae8844f6a39a3cc8ac67a0d24ae5795ca1
libpng-devel-1.6.34-8.el8_8.1.ppc64le.rpm SHA-256: 09ba71a3ecb7f0ba526093a37328ccc469d323667e3413ef28ab6f314824fff7
libpng-devel-debuginfo-1.6.34-8.el8_8.1.ppc64le.rpm SHA-256: 2e01185419f7a46615147960bfd2dc9eaab825a53daeae440aef0c475ae853f7
libpng-tools-debuginfo-1.6.34-8.el8_8.1.ppc64le.rpm SHA-256: e8cc4120e0b10f9ff6ccac02b72fa9ad714ff23c386a8791ea45bf73fd0eefe6

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8

SRPM
libpng-1.6.34-8.el8_8.1.src.rpm SHA-256: f2d41362de0e31f3a1d58e8b14c1707a3e2f966d6c9585b0c7afe8f83f7955b2
x86_64
libpng-1.6.34-8.el8_8.1.i686.rpm SHA-256: 7ab059fb75e2ea831c66544c94e6084bf449c58d030cd268e30f62b5132b62c8
libpng-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 5fde7bfe96fbe06a173144c5bf2e2cd2c3755eafd4a7b3eacc2e48b6c1848341
libpng-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: a0adaec849a4f1fce82da98e64255fe5a49414c0c71089f922b4744fe0fbb660
libpng-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 3ee6ed1db57cacfbbc7cbc2685be3843f4620e2dd73639f2825afc935c4a8eff
libpng-debugsource-1.6.34-8.el8_8.1.i686.rpm SHA-256: 21b319b6d842d20c770b4cdb2462568c4c8cc78b0bf4c56226d8915c6571b499
libpng-debugsource-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 344f99c02fc1fa51be1185eff505bbe6484e6627fc3f7598ec4b0571f8cd6f8e
libpng-devel-1.6.34-8.el8_8.1.i686.rpm SHA-256: 9209a7b57dbe5f5f538bc9721f35befb496c4ce2ec1b297f09321bc41997c384
libpng-devel-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 4d7ac27f1c095fcee5e3b044e2cfb7eec9688145bf6f8cc4bb59e9068180627e
libpng-devel-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: 9d46702eb1fdae27a940b627f51900e2cf095c81ce0db31dfa6eff1faa4f308d
libpng-devel-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 155c84d1fdf8dcfce7776ef44230b41b9d77c016d0e6efe5e3c708078e7e0a19
libpng-tools-debuginfo-1.6.34-8.el8_8.1.i686.rpm SHA-256: dc089031aefbcbc93133bd6eec0fb8e4c49cc40f1ab377f5212063d9645ad8c1
libpng-tools-debuginfo-1.6.34-8.el8_8.1.x86_64.rpm SHA-256: 7de094ac9d2ebd051e02762947c8e528ad7b4e454be1823f662cff16e37f6838

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility