Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:17567 - Security Advisory
Issued:
2026-05-14
Updated:
2026-05-14

RHSA-2026:17567 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: libpng security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libpng is now available for Red Hat Enterprise Linux 10.0 Extended Update Support.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.

Security Fix(es):

  • libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64
  • Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le
  • Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x
  • Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64

Fixes

  • BZ - 2451819 - CVE-2026-33636 libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion

CVEs

  • CVE-2026-33636

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0

SRPM
libpng-1.6.40-8.el10_0.3.src.rpm SHA-256: 1a981ca38b303fc33012c27ee0808e7fb685b29ef550365cfa0c3082ac48efb6
x86_64
libpng-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 53d587c0a27b5a748bacef8ab345a1b99aa0dd5f7953cf11ef82b43681701014
libpng-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: fd75c42ed145d4574faca65aa97f47a910abf99b9eb13fb9258acc83f3e24aa2
libpng-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: fd75c42ed145d4574faca65aa97f47a910abf99b9eb13fb9258acc83f3e24aa2
libpng-debugsource-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 17ec0b56632a1da9430c25d2cd98ed297302a65ec2a5490db052de529635a250
libpng-debugsource-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 17ec0b56632a1da9430c25d2cd98ed297302a65ec2a5490db052de529635a250
libpng-devel-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 4410c69e9731b75cf8796617b2b9985af5c616303f93bc14294fd8730b2e6528
libpng-devel-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 1ec3af64436cd29cb412290d0481b3ec4cf99773a662f23925d76a60a9ca1cdc
libpng-devel-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 1ec3af64436cd29cb412290d0481b3ec4cf99773a662f23925d76a60a9ca1cdc
libpng-tools-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: c2bc2997c382f68143fd709aac90f07357ecfc8e744d73c0a80d4e66e018e61f
libpng-tools-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: c2bc2997c382f68143fd709aac90f07357ecfc8e744d73c0a80d4e66e018e61f

Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0

SRPM
s390x
libpng-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 199833bfb86c186c3d162369c644a6881fe7fa64d5c95b38b57832401da9099b
libpng-debuginfo-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 316d6278d375837a2d39f97826a9f7b3526bf26413e629809f7abd46f3138b27
libpng-debugsource-1.6.40-8.el10_0.3.s390x.rpm SHA-256: b573504f90f5d61a30aefdd2152c2a01e1c5de1364a4d31f2f0ce0d7799385e4
libpng-devel-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 41b12daf95a8df9909f485a986dd92d969fb9636a6276dffbde42b349db88e34
libpng-devel-debuginfo-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 684b8670356ae5cbfc8829696ce8bf4a78f908f160561f73affd4e23afda1e4a
libpng-tools-debuginfo-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 089c39e292c4d5a4ed241fb9554240033a52b29c0502113d3e44e6cf056819c4

Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0

SRPM
libpng-1.6.40-8.el10_0.3.src.rpm SHA-256: 1a981ca38b303fc33012c27ee0808e7fb685b29ef550365cfa0c3082ac48efb6
ppc64le
libpng-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: cb2ded4e76f90e44fd5a043c30b67026277b67a1feb5bc5b0b66780c430a4f13
libpng-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 31ec328290f0914085896e791d036e08075d1ef2bd0edd71ea7bf9898b1e9a5e
libpng-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 31ec328290f0914085896e791d036e08075d1ef2bd0edd71ea7bf9898b1e9a5e
libpng-debugsource-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 5528d3cd77d0b79912898fa6f6d0f131eef16c2ddff8dfa59e5a8929ba35cc56
libpng-debugsource-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 5528d3cd77d0b79912898fa6f6d0f131eef16c2ddff8dfa59e5a8929ba35cc56
libpng-devel-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 83e17f4ce3a2c2ad96411428f85b0d38fac049ea426685ebd5d861caf7c35ad9
libpng-devel-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: e8caf75ae3b30f04f1491414990f52b956bd1cdec834da22070a7ac76c9164e3
libpng-devel-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: e8caf75ae3b30f04f1491414990f52b956bd1cdec834da22070a7ac76c9164e3
libpng-tools-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 6cc1c47de148c3fa0c9a03161769a363d8477cae618d2d54593a9116e0701ee4
libpng-tools-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 6cc1c47de148c3fa0c9a03161769a363d8477cae618d2d54593a9116e0701ee4

Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0

SRPM
libpng-1.6.40-8.el10_0.3.src.rpm SHA-256: 1a981ca38b303fc33012c27ee0808e7fb685b29ef550365cfa0c3082ac48efb6
aarch64
libpng-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: f171e67094147107395cd592864b6fd43b0286276e949ba6d7f628fdadfb9e50
libpng-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 798cb38cda57605ce075a215896d8155154d774db31fd62777ea1db536e5d556
libpng-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 798cb38cda57605ce075a215896d8155154d774db31fd62777ea1db536e5d556
libpng-debugsource-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 79fdb00dceebe8150713e9c8cf72af14b59ae28c5ac23f0252fcf7c1361f56fc
libpng-debugsource-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 79fdb00dceebe8150713e9c8cf72af14b59ae28c5ac23f0252fcf7c1361f56fc
libpng-devel-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 0565bb5905d187958c93ded73bb2d2a2538f8212269b58ae57c235010299d287
libpng-devel-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 81e54d87e203f03743d5db7560acde1e506de353da742bbc7546238a9ffbde2b
libpng-devel-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 81e54d87e203f03743d5db7560acde1e506de353da742bbc7546238a9ffbde2b
libpng-tools-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 731cc7daadceefc2b3581bbab00ba78f8a50f2cb42317ae78ac4a5ea94641bcc
libpng-tools-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 731cc7daadceefc2b3581bbab00ba78f8a50f2cb42317ae78ac4a5ea94641bcc

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0

SRPM
libpng-1.6.40-8.el10_0.3.src.rpm SHA-256: 1a981ca38b303fc33012c27ee0808e7fb685b29ef550365cfa0c3082ac48efb6
aarch64
libpng-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: f171e67094147107395cd592864b6fd43b0286276e949ba6d7f628fdadfb9e50
libpng-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 798cb38cda57605ce075a215896d8155154d774db31fd62777ea1db536e5d556
libpng-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 798cb38cda57605ce075a215896d8155154d774db31fd62777ea1db536e5d556
libpng-debugsource-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 79fdb00dceebe8150713e9c8cf72af14b59ae28c5ac23f0252fcf7c1361f56fc
libpng-debugsource-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 79fdb00dceebe8150713e9c8cf72af14b59ae28c5ac23f0252fcf7c1361f56fc
libpng-devel-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 0565bb5905d187958c93ded73bb2d2a2538f8212269b58ae57c235010299d287
libpng-devel-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 81e54d87e203f03743d5db7560acde1e506de353da742bbc7546238a9ffbde2b
libpng-devel-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 81e54d87e203f03743d5db7560acde1e506de353da742bbc7546238a9ffbde2b
libpng-tools-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 731cc7daadceefc2b3581bbab00ba78f8a50f2cb42317ae78ac4a5ea94641bcc
libpng-tools-debuginfo-1.6.40-8.el10_0.3.aarch64.rpm SHA-256: 731cc7daadceefc2b3581bbab00ba78f8a50f2cb42317ae78ac4a5ea94641bcc

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0

SRPM
s390x
libpng-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 199833bfb86c186c3d162369c644a6881fe7fa64d5c95b38b57832401da9099b
libpng-debuginfo-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 316d6278d375837a2d39f97826a9f7b3526bf26413e629809f7abd46f3138b27
libpng-debugsource-1.6.40-8.el10_0.3.s390x.rpm SHA-256: b573504f90f5d61a30aefdd2152c2a01e1c5de1364a4d31f2f0ce0d7799385e4
libpng-devel-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 41b12daf95a8df9909f485a986dd92d969fb9636a6276dffbde42b349db88e34
libpng-devel-debuginfo-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 684b8670356ae5cbfc8829696ce8bf4a78f908f160561f73affd4e23afda1e4a
libpng-tools-debuginfo-1.6.40-8.el10_0.3.s390x.rpm SHA-256: 089c39e292c4d5a4ed241fb9554240033a52b29c0502113d3e44e6cf056819c4

Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0

SRPM
libpng-1.6.40-8.el10_0.3.src.rpm SHA-256: 1a981ca38b303fc33012c27ee0808e7fb685b29ef550365cfa0c3082ac48efb6
ppc64le
libpng-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: cb2ded4e76f90e44fd5a043c30b67026277b67a1feb5bc5b0b66780c430a4f13
libpng-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 31ec328290f0914085896e791d036e08075d1ef2bd0edd71ea7bf9898b1e9a5e
libpng-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 31ec328290f0914085896e791d036e08075d1ef2bd0edd71ea7bf9898b1e9a5e
libpng-debugsource-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 5528d3cd77d0b79912898fa6f6d0f131eef16c2ddff8dfa59e5a8929ba35cc56
libpng-debugsource-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 5528d3cd77d0b79912898fa6f6d0f131eef16c2ddff8dfa59e5a8929ba35cc56
libpng-devel-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 83e17f4ce3a2c2ad96411428f85b0d38fac049ea426685ebd5d861caf7c35ad9
libpng-devel-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: e8caf75ae3b30f04f1491414990f52b956bd1cdec834da22070a7ac76c9164e3
libpng-devel-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: e8caf75ae3b30f04f1491414990f52b956bd1cdec834da22070a7ac76c9164e3
libpng-tools-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 6cc1c47de148c3fa0c9a03161769a363d8477cae618d2d54593a9116e0701ee4
libpng-tools-debuginfo-1.6.40-8.el10_0.3.ppc64le.rpm SHA-256: 6cc1c47de148c3fa0c9a03161769a363d8477cae618d2d54593a9116e0701ee4

Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0

SRPM
libpng-1.6.40-8.el10_0.3.src.rpm SHA-256: 1a981ca38b303fc33012c27ee0808e7fb685b29ef550365cfa0c3082ac48efb6
x86_64
libpng-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 53d587c0a27b5a748bacef8ab345a1b99aa0dd5f7953cf11ef82b43681701014
libpng-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: fd75c42ed145d4574faca65aa97f47a910abf99b9eb13fb9258acc83f3e24aa2
libpng-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: fd75c42ed145d4574faca65aa97f47a910abf99b9eb13fb9258acc83f3e24aa2
libpng-debugsource-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 17ec0b56632a1da9430c25d2cd98ed297302a65ec2a5490db052de529635a250
libpng-debugsource-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 17ec0b56632a1da9430c25d2cd98ed297302a65ec2a5490db052de529635a250
libpng-devel-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 4410c69e9731b75cf8796617b2b9985af5c616303f93bc14294fd8730b2e6528
libpng-devel-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 1ec3af64436cd29cb412290d0481b3ec4cf99773a662f23925d76a60a9ca1cdc
libpng-devel-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: 1ec3af64436cd29cb412290d0481b3ec4cf99773a662f23925d76a60a9ca1cdc
libpng-tools-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: c2bc2997c382f68143fd709aac90f07357ecfc8e744d73c0a80d4e66e018e61f
libpng-tools-debuginfo-1.6.40-8.el10_0.3.x86_64.rpm SHA-256: c2bc2997c382f68143fd709aac90f07357ecfc8e744d73c0a80d4e66e018e61f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility