Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3573 - Security Advisory
Issued:
2026-03-02
Updated:
2026-03-02

RHSA-2026:3573 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libpng security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libpng is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.

Security Fix(es):

  • libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801)
  • libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695)
  • libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0 s390x

Fixes

  • BZ - 2428824 - CVE-2026-22801 libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
  • BZ - 2428825 - CVE-2026-22695 libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
  • BZ - 2438542 - CVE-2026-25646 libpng: LIBPNG has a heap buffer overflow in png_set_quantize

CVEs

  • CVE-2026-22695
  • CVE-2026-22801
  • CVE-2026-25646

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.0

SRPM
libpng-1.6.37-12.el9_0.2.src.rpm SHA-256: 6526bc693ae341e083110023958f417913fb96a7ad3447e930d301288193148c
ppc64le
libpng-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: 7860cd57feaed41123404bf648fcd4bab6cdb732ac1e39531da7726f66b5c30d
libpng-debuginfo-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: 9670273d776d88e078f59b16e9d5f110bba9fbb3c6512a07c97b99b9ae234999
libpng-debuginfo-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: 9670273d776d88e078f59b16e9d5f110bba9fbb3c6512a07c97b99b9ae234999
libpng-debugsource-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: 17ff6c86223923fd733e285d8c4d89ba55d63f77c2f87a8ececd2b901f459cde
libpng-debugsource-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: 17ff6c86223923fd733e285d8c4d89ba55d63f77c2f87a8ececd2b901f459cde
libpng-devel-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: 3451b01a5e29a4f60defdc0ce79556df0a24f62437e0871020bac40696c08a1c
libpng-devel-debuginfo-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: d1cbb30e10cd1aa9ea2e074babea13b8616e6dea6d59093ca2aaeaae3dccc678
libpng-devel-debuginfo-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: d1cbb30e10cd1aa9ea2e074babea13b8616e6dea6d59093ca2aaeaae3dccc678
libpng-tools-debuginfo-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: 6b41e30b478db17f0c9e2203a17dab8c6ac35977604877dcf15d5ad598301364
libpng-tools-debuginfo-1.6.37-12.el9_0.2.ppc64le.rpm SHA-256: 6b41e30b478db17f0c9e2203a17dab8c6ac35977604877dcf15d5ad598301364

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
libpng-1.6.37-12.el9_0.2.src.rpm SHA-256: 6526bc693ae341e083110023958f417913fb96a7ad3447e930d301288193148c
x86_64
libpng-1.6.37-12.el9_0.2.i686.rpm SHA-256: 8b1a7a57e81e1e999ce19784a5bbd53119d11685123931104f05ca48802a6d11
libpng-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: 82180383a75ba3e4d9b21aff8fb20bcddf044ca6f56e195006377ebb7fefbd57
libpng-debuginfo-1.6.37-12.el9_0.2.i686.rpm SHA-256: cd0d3a47a2d42ea8c043eb0d444e04c471ea466a086cc3857268a623b005049a
libpng-debuginfo-1.6.37-12.el9_0.2.i686.rpm SHA-256: cd0d3a47a2d42ea8c043eb0d444e04c471ea466a086cc3857268a623b005049a
libpng-debuginfo-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: 7df1a96dfe590d57e6b4b1def0ccbc534503124b2bc8fa329782a533daf4b648
libpng-debuginfo-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: 7df1a96dfe590d57e6b4b1def0ccbc534503124b2bc8fa329782a533daf4b648
libpng-debugsource-1.6.37-12.el9_0.2.i686.rpm SHA-256: 79ff6ee2b3599e59e88e2b806b5796a70023f57b241da06d4a7f1d6d1d4718bc
libpng-debugsource-1.6.37-12.el9_0.2.i686.rpm SHA-256: 79ff6ee2b3599e59e88e2b806b5796a70023f57b241da06d4a7f1d6d1d4718bc
libpng-debugsource-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: ec9da3730f2dc8098b5f5ff84b895de6851868edd4dc753e3cfb4e1bf436cdd4
libpng-debugsource-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: ec9da3730f2dc8098b5f5ff84b895de6851868edd4dc753e3cfb4e1bf436cdd4
libpng-devel-1.6.37-12.el9_0.2.i686.rpm SHA-256: cae6494ba07f0cf14d16b5227af4dfb7ddc9adaf476de287f0094ef1bffd3f72
libpng-devel-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: 3d19a798d198f5d97b6485c2477553f7c4fdb4558cad33e93726fa91e7b8ed4b
libpng-devel-debuginfo-1.6.37-12.el9_0.2.i686.rpm SHA-256: 97fe8ab060c9b4ac862dea7a233652a7dd263853504825c5ffc7a5f7ad8ea4ce
libpng-devel-debuginfo-1.6.37-12.el9_0.2.i686.rpm SHA-256: 97fe8ab060c9b4ac862dea7a233652a7dd263853504825c5ffc7a5f7ad8ea4ce
libpng-devel-debuginfo-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: 90575e97e0d60b5c03f12cfccecb53e617dfc800819eaf716f403e10f17b116a
libpng-devel-debuginfo-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: 90575e97e0d60b5c03f12cfccecb53e617dfc800819eaf716f403e10f17b116a
libpng-tools-debuginfo-1.6.37-12.el9_0.2.i686.rpm SHA-256: 3e2d00471f6d43900aa5b49dd2102011c3efd8588ce384fa0188fcaac0006ca6
libpng-tools-debuginfo-1.6.37-12.el9_0.2.i686.rpm SHA-256: 3e2d00471f6d43900aa5b49dd2102011c3efd8588ce384fa0188fcaac0006ca6
libpng-tools-debuginfo-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: a3f59a0df99a1e5697ca2859edef7168297a5fffd0e69519323e69de5fe48643
libpng-tools-debuginfo-1.6.37-12.el9_0.2.x86_64.rpm SHA-256: a3f59a0df99a1e5697ca2859edef7168297a5fffd0e69519323e69de5fe48643

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.0

SRPM
libpng-1.6.37-12.el9_0.2.src.rpm SHA-256: 6526bc693ae341e083110023958f417913fb96a7ad3447e930d301288193148c
aarch64
libpng-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: 73e5b016423e59de4f76f77c5ed7660b9d639c29b8a2a049a0a4759f6b7ccfa5
libpng-debuginfo-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: 2ad217c0ca14efbb4ab5ec61a280922e75e542b09d8666d20d958870b9598dc5
libpng-debuginfo-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: 2ad217c0ca14efbb4ab5ec61a280922e75e542b09d8666d20d958870b9598dc5
libpng-debugsource-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: ae0b678c60288277eb5ee1d3896cd62eeb2c18d07a5b40b795ae29bdb0a3c02f
libpng-debugsource-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: ae0b678c60288277eb5ee1d3896cd62eeb2c18d07a5b40b795ae29bdb0a3c02f
libpng-devel-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: f59fd902152d19699896c9ae97fcc5477c52984fac8557f0014e14995db8def2
libpng-devel-debuginfo-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: ebd04f4ea2e4d4114cefc2c6d09702de915d12773761fe4c729e0cd935b20ae5
libpng-devel-debuginfo-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: ebd04f4ea2e4d4114cefc2c6d09702de915d12773761fe4c729e0cd935b20ae5
libpng-tools-debuginfo-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: 1fa78b39c93c51bafa8f3e81aa87595410ef4ee21b98f9bbcbbb6baa06bae4e5
libpng-tools-debuginfo-1.6.37-12.el9_0.2.aarch64.rpm SHA-256: 1fa78b39c93c51bafa8f3e81aa87595410ef4ee21b98f9bbcbbb6baa06bae4e5

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.0

SRPM
s390x
libpng-1.6.37-12.el9_0.2.s390x.rpm SHA-256: de5fe0bba30bc886f8bc5cc6481fab0d8f609381b23e683cc4136572a3b9677c
libpng-debuginfo-1.6.37-12.el9_0.2.s390x.rpm SHA-256: 522034d1f34eb875986be65b358182af5bc8e59845da1bcfe2c22f4ffc6152b9
libpng-debugsource-1.6.37-12.el9_0.2.s390x.rpm SHA-256: 1512fe1ff139811a64912804bbc2d2a6d6a6ab24d8996b4c708ba87cce0e1e37
libpng-devel-1.6.37-12.el9_0.2.s390x.rpm SHA-256: 2394f7be93da4d33c1c8e48c846b7a87e81f2e559ff49c0a65e4a8d9bbd473e5
libpng-devel-debuginfo-1.6.37-12.el9_0.2.s390x.rpm SHA-256: e92ef41cb281783b2a9d93afb55a5ac835b0587441a28f197f620081f811bb0f
libpng-tools-debuginfo-1.6.37-12.el9_0.2.s390x.rpm SHA-256: c65da3b405ff5d73913cdc7f922a419c446a1d3c0238edad96dfd5ab43f98595

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility