Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3575 - Security Advisory
Issued:
2026-03-02
Updated:
2026-03-02

RHSA-2026:3575 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libpng security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libpng is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.

Security Fix(es):

  • libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801)
  • libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695)
  • libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x

Fixes

  • BZ - 2428824 - CVE-2026-22801 libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API
  • BZ - 2428825 - CVE-2026-22695 libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read
  • BZ - 2438542 - CVE-2026-25646 libpng: LIBPNG has a heap buffer overflow in png_set_quantize

CVEs

  • CVE-2026-22695
  • CVE-2026-22801
  • CVE-2026-25646

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
libpng-1.6.37-12.el9_2.2.src.rpm SHA-256: c3535a5bea54f07c5a616e78c7d2b9eb80288b019b15173c42b604ae91c41834
x86_64
libpng-1.6.37-12.el9_2.2.i686.rpm SHA-256: 58156b9c314b9e8384c33b5bb146d91588f0d68046781dc14c92201601f58d17
libpng-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 4344fa1796da8114c6de104515672794fb649b0614cc076884d48881734b632b
libpng-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: b1a24b2a186170c5360f6fc1919467ee008310aa55579e0a89ed49c72e63c20d
libpng-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: b1a24b2a186170c5360f6fc1919467ee008310aa55579e0a89ed49c72e63c20d
libpng-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 6c114ff51263decb6937792d403575f646b8f1fa9ced40f74647bfbf516c0166
libpng-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 6c114ff51263decb6937792d403575f646b8f1fa9ced40f74647bfbf516c0166
libpng-debugsource-1.6.37-12.el9_2.2.i686.rpm SHA-256: 7fe87d7419a0fd525597ce8ddc82b43c485945514b4a2cf6b42b92d26d5f80df
libpng-debugsource-1.6.37-12.el9_2.2.i686.rpm SHA-256: 7fe87d7419a0fd525597ce8ddc82b43c485945514b4a2cf6b42b92d26d5f80df
libpng-debugsource-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: b570629bfcf5634a648219f27fcb6b278771cb0d77b36331545789f9277e5f53
libpng-debugsource-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: b570629bfcf5634a648219f27fcb6b278771cb0d77b36331545789f9277e5f53
libpng-devel-1.6.37-12.el9_2.2.i686.rpm SHA-256: dd67cef81ce917231b1799876f85632fefc5ed8ecf021cc67cf5e3ff26527202
libpng-devel-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 64c1df12e29cbe731de4dd9f29800acb16b7c7990c573f9ba77106e5b49ccc67
libpng-devel-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: 8f302eca68547667752fcc5bbeab2232314e5c7cc5e4a35c7d922bbc13a647fa
libpng-devel-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: 8f302eca68547667752fcc5bbeab2232314e5c7cc5e4a35c7d922bbc13a647fa
libpng-devel-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 093b1ef592536389e8e4d0e27f03ef212543ca640d0cd47a5a5fec874c8cfa17
libpng-devel-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 093b1ef592536389e8e4d0e27f03ef212543ca640d0cd47a5a5fec874c8cfa17
libpng-tools-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: 31b30450d6ef67e6eac39997b9ff7417a88402ce0c180bbcd23dd0d4a62c993d
libpng-tools-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: 31b30450d6ef67e6eac39997b9ff7417a88402ce0c180bbcd23dd0d4a62c993d
libpng-tools-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: d313090fcbda5d56049531392b190a2545df635e36eede05eae9a771cd59d7e3
libpng-tools-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: d313090fcbda5d56049531392b190a2545df635e36eede05eae9a771cd59d7e3

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
libpng-1.6.37-12.el9_2.2.src.rpm SHA-256: c3535a5bea54f07c5a616e78c7d2b9eb80288b019b15173c42b604ae91c41834
ppc64le
libpng-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 42ed706d27c1e75d1eea8dc8b17369e822ad1302c53e9836fc262899a50323c7
libpng-debuginfo-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 1b5d7ee96c8e3817a5e2550a23ee61839d7663447254f47e456ba631f04de2bd
libpng-debuginfo-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 1b5d7ee96c8e3817a5e2550a23ee61839d7663447254f47e456ba631f04de2bd
libpng-debugsource-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 542a03aef913d69e6e488659b4116e2f6b9c34bc8c16a460c042b12473222cb6
libpng-debugsource-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 542a03aef913d69e6e488659b4116e2f6b9c34bc8c16a460c042b12473222cb6
libpng-devel-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 3fe9cc42e81cef08c4a795e2fc750925dd59894bf4c7cc4ccc32aa7fdca437d8
libpng-devel-debuginfo-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 02dbf93523f05bba4a768601b060db6fd9f54f65308de68282d94bc5398d9fba
libpng-devel-debuginfo-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 02dbf93523f05bba4a768601b060db6fd9f54f65308de68282d94bc5398d9fba
libpng-tools-debuginfo-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 693a493c55363d99c4724c9f48e38748666d5e4903c0cce13b1a9d354c9e3fe3
libpng-tools-debuginfo-1.6.37-12.el9_2.2.ppc64le.rpm SHA-256: 693a493c55363d99c4724c9f48e38748666d5e4903c0cce13b1a9d354c9e3fe3

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
libpng-1.6.37-12.el9_2.2.src.rpm SHA-256: c3535a5bea54f07c5a616e78c7d2b9eb80288b019b15173c42b604ae91c41834
x86_64
libpng-1.6.37-12.el9_2.2.i686.rpm SHA-256: 58156b9c314b9e8384c33b5bb146d91588f0d68046781dc14c92201601f58d17
libpng-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 4344fa1796da8114c6de104515672794fb649b0614cc076884d48881734b632b
libpng-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: b1a24b2a186170c5360f6fc1919467ee008310aa55579e0a89ed49c72e63c20d
libpng-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: b1a24b2a186170c5360f6fc1919467ee008310aa55579e0a89ed49c72e63c20d
libpng-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 6c114ff51263decb6937792d403575f646b8f1fa9ced40f74647bfbf516c0166
libpng-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 6c114ff51263decb6937792d403575f646b8f1fa9ced40f74647bfbf516c0166
libpng-debugsource-1.6.37-12.el9_2.2.i686.rpm SHA-256: 7fe87d7419a0fd525597ce8ddc82b43c485945514b4a2cf6b42b92d26d5f80df
libpng-debugsource-1.6.37-12.el9_2.2.i686.rpm SHA-256: 7fe87d7419a0fd525597ce8ddc82b43c485945514b4a2cf6b42b92d26d5f80df
libpng-debugsource-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: b570629bfcf5634a648219f27fcb6b278771cb0d77b36331545789f9277e5f53
libpng-debugsource-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: b570629bfcf5634a648219f27fcb6b278771cb0d77b36331545789f9277e5f53
libpng-devel-1.6.37-12.el9_2.2.i686.rpm SHA-256: dd67cef81ce917231b1799876f85632fefc5ed8ecf021cc67cf5e3ff26527202
libpng-devel-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 64c1df12e29cbe731de4dd9f29800acb16b7c7990c573f9ba77106e5b49ccc67
libpng-devel-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: 8f302eca68547667752fcc5bbeab2232314e5c7cc5e4a35c7d922bbc13a647fa
libpng-devel-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: 8f302eca68547667752fcc5bbeab2232314e5c7cc5e4a35c7d922bbc13a647fa
libpng-devel-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 093b1ef592536389e8e4d0e27f03ef212543ca640d0cd47a5a5fec874c8cfa17
libpng-devel-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: 093b1ef592536389e8e4d0e27f03ef212543ca640d0cd47a5a5fec874c8cfa17
libpng-tools-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: 31b30450d6ef67e6eac39997b9ff7417a88402ce0c180bbcd23dd0d4a62c993d
libpng-tools-debuginfo-1.6.37-12.el9_2.2.i686.rpm SHA-256: 31b30450d6ef67e6eac39997b9ff7417a88402ce0c180bbcd23dd0d4a62c993d
libpng-tools-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: d313090fcbda5d56049531392b190a2545df635e36eede05eae9a771cd59d7e3
libpng-tools-debuginfo-1.6.37-12.el9_2.2.x86_64.rpm SHA-256: d313090fcbda5d56049531392b190a2545df635e36eede05eae9a771cd59d7e3

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
libpng-1.6.37-12.el9_2.2.src.rpm SHA-256: c3535a5bea54f07c5a616e78c7d2b9eb80288b019b15173c42b604ae91c41834
aarch64
libpng-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: e968f11fe70a5decf73a5c0a62b4bd658e5c66b12dbe1ffe25e963a86d245214
libpng-debuginfo-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: dce43e03a8555bd9a266b329081b393a7ccc903e010fb2a8849be8d358622847
libpng-debuginfo-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: dce43e03a8555bd9a266b329081b393a7ccc903e010fb2a8849be8d358622847
libpng-debugsource-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: b7b29900628f10f22a3d137d0745b147180a1ea144b7f7d276684c84a7a87764
libpng-debugsource-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: b7b29900628f10f22a3d137d0745b147180a1ea144b7f7d276684c84a7a87764
libpng-devel-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: 2fc2d42066dae88cd03785c13417080aba10adf240b1f7a99ddb304d1c13bf97
libpng-devel-debuginfo-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: 3a96da9e41b8685bcc3b5247382a17b9eec9494c144dcb1ba8218e79f09a59ff
libpng-devel-debuginfo-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: 3a96da9e41b8685bcc3b5247382a17b9eec9494c144dcb1ba8218e79f09a59ff
libpng-tools-debuginfo-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: c632b42d06d9edfccd71b5ce2f82ae0c0b6032bdf0156c330d1b5959cb50248e
libpng-tools-debuginfo-1.6.37-12.el9_2.2.aarch64.rpm SHA-256: c632b42d06d9edfccd71b5ce2f82ae0c0b6032bdf0156c330d1b5959cb50248e

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
s390x
libpng-1.6.37-12.el9_2.2.s390x.rpm SHA-256: e97cb2c52ff513e51c519e2624c623c48dcda695c72884ba9f15d567df6c669e
libpng-debuginfo-1.6.37-12.el9_2.2.s390x.rpm SHA-256: 42ee04638864593df8e3a3016940a78343cbc15342056f02b7a4b6eff040d2eb
libpng-debugsource-1.6.37-12.el9_2.2.s390x.rpm SHA-256: 9e74bf68a5efa5dfb359a32b3caccda089e260e691c34fb6cd681e6bde9f4577
libpng-devel-1.6.37-12.el9_2.2.s390x.rpm SHA-256: 69aa29d7a22b88d74340d7205eeec68ac6e5c37f121b851542b5e1cb056f064c
libpng-devel-debuginfo-1.6.37-12.el9_2.2.s390x.rpm SHA-256: e4163b06c91c922a225abf906c7e2429296fb9c0b0c31e0de31935c0faaeaba9
libpng-tools-debuginfo-1.6.37-12.el9_2.2.s390x.rpm SHA-256: 52ff0514aaffb244c739d17f133ff34d0319bb10dd8ee4766d1a6296162c3179

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility