Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3551 - Security Advisory
Issued:
2026-03-02
Updated:
2026-03-02

RHSA-2026:3551 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libpng security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libpng is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.

Security Fix(es):

  • libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801)
  • libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695)
  • libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2428824 - CVE-2026-22801 libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
  • BZ - 2428825 - CVE-2026-22695 libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
  • BZ - 2438542 - CVE-2026-25646 libpng: LIBPNG has a heap buffer overflow in png_set_quantize

CVEs

  • CVE-2026-22695
  • CVE-2026-22801
  • CVE-2026-25646

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
libpng-1.6.40-8.el10_1.2.src.rpm SHA-256: 035112dcd24967e5f9ac7367bfba1bd6c9b6dec64a8b79f393185fb37b555b1e
x86_64
libpng-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: 6117aece514deeb186f57872b661d7f6a685a1272beacdf37904707a15edb991
libpng-debuginfo-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: ba0eda1a6d0d921d5460f001010fba98a3b4993811eb22c954729c8bf8c1d656
libpng-debuginfo-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: ba0eda1a6d0d921d5460f001010fba98a3b4993811eb22c954729c8bf8c1d656
libpng-debugsource-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: dcb35f57d1200ee2ecf7e178a14295b74049e78c86420da11e9a4297de15a591
libpng-debugsource-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: dcb35f57d1200ee2ecf7e178a14295b74049e78c86420da11e9a4297de15a591
libpng-devel-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: 2b0098667829b74b5e648695cff31e9de03e5286b9255feb77e9223679bd89d2
libpng-devel-debuginfo-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: e7d6c674c18e10b7f270d963247c3df5561527146f6e0b2a843e8b4e8371f622
libpng-devel-debuginfo-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: e7d6c674c18e10b7f270d963247c3df5561527146f6e0b2a843e8b4e8371f622
libpng-tools-debuginfo-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: 640dd184f968359617eb8ca3e101dab4e6855a45016d0180571f3c22c56a6099
libpng-tools-debuginfo-1.6.40-8.el10_1.2.x86_64.rpm SHA-256: 640dd184f968359617eb8ca3e101dab4e6855a45016d0180571f3c22c56a6099

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
s390x
libpng-1.6.40-8.el10_1.2.s390x.rpm SHA-256: d38e04a755888c1d0728c5df37bf3a668150c40dd9893324126e3ba7de1a1b1b
libpng-debuginfo-1.6.40-8.el10_1.2.s390x.rpm SHA-256: b34e71a1999e56e5adc79f440b0ef1fd5976f37c082a7861481842835b6af297
libpng-debugsource-1.6.40-8.el10_1.2.s390x.rpm SHA-256: aab09f2837bd376bfe342fbc1f8d8a9014a03dd1be817283996d076fca3ff307
libpng-devel-1.6.40-8.el10_1.2.s390x.rpm SHA-256: 5bb66108b1f9b8e08ba0b2028b8d8b4e14ae33fbab16493a87d961d1700e07fb
libpng-devel-debuginfo-1.6.40-8.el10_1.2.s390x.rpm SHA-256: a20adc9d1f84bd7ec9c65c3fb50973aed07dead3ef1cb0b5f15b40ca3cfb7c58
libpng-tools-debuginfo-1.6.40-8.el10_1.2.s390x.rpm SHA-256: bebd490820fcf908c49e40f7d209bcdea1941925002ed671d469d865a2ce5beb

Red Hat Enterprise Linux for Power, little endian 10

SRPM
libpng-1.6.40-8.el10_1.2.src.rpm SHA-256: 035112dcd24967e5f9ac7367bfba1bd6c9b6dec64a8b79f393185fb37b555b1e
ppc64le
libpng-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: 792b8a1d20173f583daaaddf5a73e901588626e01824322a8f6c2fdeb7c49d40
libpng-debuginfo-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: a5ac7762a5577657e06db3a539f9c1d7b282dc3a2b7d40be2952ec9972fd2159
libpng-debuginfo-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: a5ac7762a5577657e06db3a539f9c1d7b282dc3a2b7d40be2952ec9972fd2159
libpng-debugsource-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: 25198beb975024f77e434fe4c1de64e82c7f6c21b70b494206c1bbefcfb7f05e
libpng-debugsource-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: 25198beb975024f77e434fe4c1de64e82c7f6c21b70b494206c1bbefcfb7f05e
libpng-devel-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: 6de3f09bdd633ab8f14e6478cbee476bbf8a56746b498bccb98e36a2b2198590
libpng-devel-debuginfo-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: 1f5e05f4c9d3bec01970207e1bbee86914f7bd3aeafe04f82f1fe2fd1ad7986e
libpng-devel-debuginfo-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: 1f5e05f4c9d3bec01970207e1bbee86914f7bd3aeafe04f82f1fe2fd1ad7986e
libpng-tools-debuginfo-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: b3bc66fc40a6f57dea8212001e3acd7b023f99bf8edb9cd7e923f8b4ec939fb1
libpng-tools-debuginfo-1.6.40-8.el10_1.2.ppc64le.rpm SHA-256: b3bc66fc40a6f57dea8212001e3acd7b023f99bf8edb9cd7e923f8b4ec939fb1

Red Hat Enterprise Linux for ARM 64 10

SRPM
libpng-1.6.40-8.el10_1.2.src.rpm SHA-256: 035112dcd24967e5f9ac7367bfba1bd6c9b6dec64a8b79f393185fb37b555b1e
aarch64
libpng-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: d80b4f946be2bceea778aec78676df3790a8d17a7430e51e6d686ab2c8a3a21d
libpng-debuginfo-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: e42fd65618dff2ef3e73b636d6ef04dabfea535e47007caa900bc7365bc7827d
libpng-debuginfo-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: e42fd65618dff2ef3e73b636d6ef04dabfea535e47007caa900bc7365bc7827d
libpng-debugsource-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: fb7f662d4a1f0fd1d13ef3caa8d304c10ba09ce9cd55085c9a20ad4598961528
libpng-debugsource-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: fb7f662d4a1f0fd1d13ef3caa8d304c10ba09ce9cd55085c9a20ad4598961528
libpng-devel-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: 91cc27352a463c28e9c3b200a8874c928c9918b73d74cc59693bbdbe9bd96ae4
libpng-devel-debuginfo-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: aa5162a6d2616daf8c42aee45b7253b73f358b960cdc9f772772fcba2eb4d858
libpng-devel-debuginfo-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: aa5162a6d2616daf8c42aee45b7253b73f358b960cdc9f772772fcba2eb4d858
libpng-tools-debuginfo-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: 44f0e977f09856acfe06bd70ec9d8d19cb4301bf08b465170a76180aa3812f64
libpng-tools-debuginfo-1.6.40-8.el10_1.2.aarch64.rpm SHA-256: 44f0e977f09856acfe06bd70ec9d8d19cb4301bf08b465170a76180aa3812f64

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility