Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:4756 - Security Advisory
Issued:
2026-03-17
Updated:
2026-03-17

RHSA-2026:4756 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libpng security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libpng is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.

Security Fix(es):

  • libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - Extended Life Cycle Support 7 x86_64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7 s390x
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7 ppc64
  • Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7 ppc64le

Fixes

  • BZ - 2438542 - CVE-2026-25646 libpng: LIBPNG has a heap buffer overflow in png_set_quantize

CVEs

  • CVE-2026-25646

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - Extended Life Cycle Support 7

SRPM
libpng-1.5.13-8.el7_9.2.src.rpm SHA-256: 40357b49bc279b939128586b91e9fdc40946d8ebef9c8afdb2357d42d7546089
x86_64
libpng-1.5.13-8.el7_9.2.i686.rpm SHA-256: a6070fc677d63f81bbb1065c8228bec2c97a966937dca0ce29e42d6d5f5e5e63
libpng-1.5.13-8.el7_9.2.x86_64.rpm SHA-256: adecf5373a14b892689bcd5149bd55e58c3fa68189eba56439aa3e66ffab7912
libpng-debuginfo-1.5.13-8.el7_9.2.i686.rpm SHA-256: 399073a0696fa43345b54a6e2567b325dba9fb088ce8569f1ffc870c5b47a092
libpng-debuginfo-1.5.13-8.el7_9.2.i686.rpm SHA-256: 399073a0696fa43345b54a6e2567b325dba9fb088ce8569f1ffc870c5b47a092
libpng-debuginfo-1.5.13-8.el7_9.2.x86_64.rpm SHA-256: 7537fb38d9666e61ddaac3e384cf779e4e0b0ba693318fa828a502ccbecc25fe
libpng-debuginfo-1.5.13-8.el7_9.2.x86_64.rpm SHA-256: 7537fb38d9666e61ddaac3e384cf779e4e0b0ba693318fa828a502ccbecc25fe
libpng-devel-1.5.13-8.el7_9.2.i686.rpm SHA-256: 40b423ef3085f999366681062691404e6c926024cdc851b7718528fd5c82f53e
libpng-devel-1.5.13-8.el7_9.2.x86_64.rpm SHA-256: 1b22f46358c93c8b19832abefc00de24794849599203448eddccb05ebea963c1
libpng-static-1.5.13-8.el7_9.2.i686.rpm SHA-256: 70ca26afa8b01726c5185fc6e226d646f77fbbc2c64cd78a02cda251b2ec9fee
libpng-static-1.5.13-8.el7_9.2.x86_64.rpm SHA-256: 59b5c40bbd80c497e06d59449847c4504ed8e35943c41133ebedf682e5d48f65

Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems) 7

SRPM
libpng-1.5.13-8.el7_9.2.src.rpm SHA-256: 40357b49bc279b939128586b91e9fdc40946d8ebef9c8afdb2357d42d7546089
s390x
libpng-1.5.13-8.el7_9.2.s390.rpm SHA-256: 5b6e1859c784c5bbf64359e6616701c8e318215f8185c14f88a0097083d36859
libpng-1.5.13-8.el7_9.2.s390x.rpm SHA-256: 5b2185321041af16f9ba85ae8a2c0f75813a71fed9db6459c8b189ef5e4c92d7
libpng-debuginfo-1.5.13-8.el7_9.2.s390.rpm SHA-256: bb976beb7e5d772a6fd4e79c26bfa21f26ba44310384ea0477d906da4f32adcb
libpng-debuginfo-1.5.13-8.el7_9.2.s390.rpm SHA-256: bb976beb7e5d772a6fd4e79c26bfa21f26ba44310384ea0477d906da4f32adcb
libpng-debuginfo-1.5.13-8.el7_9.2.s390x.rpm SHA-256: 3f078e0338f57977741d4bf8dfbc0618ffc453742702d257f434afb4b4cb3c9d
libpng-debuginfo-1.5.13-8.el7_9.2.s390x.rpm SHA-256: 3f078e0338f57977741d4bf8dfbc0618ffc453742702d257f434afb4b4cb3c9d
libpng-devel-1.5.13-8.el7_9.2.s390.rpm SHA-256: a244b2b2cc78d77a5e83298078487f354396d337ec0b6510b2da0c6afd902b88
libpng-devel-1.5.13-8.el7_9.2.s390x.rpm SHA-256: a3ee71f5dbfe28fc0527d1e7a0d2c0524d85c32ed3410848e21fedec8171a3fd
libpng-static-1.5.13-8.el7_9.2.s390.rpm SHA-256: f8b473b127b4ae83eefe243ebeb4af4755cf4d73e5334e34609d3a68f66d3894
libpng-static-1.5.13-8.el7_9.2.s390x.rpm SHA-256: 464761f0610f61171c40cc57e0551dd357c428fbc6b23d06494f6e37e6a857f3

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, big endian 7

SRPM
libpng-1.5.13-8.el7_9.2.src.rpm SHA-256: 40357b49bc279b939128586b91e9fdc40946d8ebef9c8afdb2357d42d7546089
ppc64
libpng-1.5.13-8.el7_9.2.ppc.rpm SHA-256: a198f64d62c84f96d192a752fe0c0354365bfa68d1138704f55109464adeb2f0
libpng-1.5.13-8.el7_9.2.ppc64.rpm SHA-256: d96a15794517fdafad293edc9e400fb264b17288f491b4e1258d627f65837f0c
libpng-debuginfo-1.5.13-8.el7_9.2.ppc.rpm SHA-256: 64bf2905603d2fb991480af9e02eb3c17b72c3ef616978731600de5e5e9958a0
libpng-debuginfo-1.5.13-8.el7_9.2.ppc.rpm SHA-256: 64bf2905603d2fb991480af9e02eb3c17b72c3ef616978731600de5e5e9958a0
libpng-debuginfo-1.5.13-8.el7_9.2.ppc64.rpm SHA-256: 134d52d471f72a78c349de3ffe55b61e47a695a83f0893abd595d2fec001dc62
libpng-debuginfo-1.5.13-8.el7_9.2.ppc64.rpm SHA-256: 134d52d471f72a78c349de3ffe55b61e47a695a83f0893abd595d2fec001dc62
libpng-devel-1.5.13-8.el7_9.2.ppc.rpm SHA-256: 41e2a63ba07f5817674dac6dd4cf84c65e153e8c08d23f9c808032fd92282640
libpng-devel-1.5.13-8.el7_9.2.ppc64.rpm SHA-256: 0c0350a5446565f908396a978e91d0fb9ef4fc2fb72190c717bdce0c4092de84
libpng-static-1.5.13-8.el7_9.2.ppc.rpm SHA-256: 7bebfd97e00bef92ed21f010c0f3d23912f949b3f39294a224a1591bf65b47a3
libpng-static-1.5.13-8.el7_9.2.ppc64.rpm SHA-256: 2eba8942dc5dfa629fa05967ce25f1abc8460ddd57255998c173ad639225c5c5

Red Hat Enterprise Linux Server - Extended Life Cycle Support for IBM Power, little endian 7

SRPM
libpng-1.5.13-8.el7_9.2.src.rpm SHA-256: 40357b49bc279b939128586b91e9fdc40946d8ebef9c8afdb2357d42d7546089
ppc64le
libpng-1.5.13-8.el7_9.2.ppc64le.rpm SHA-256: 7b62ae17b3ef3652b057a4ea6f7d1fe9e751f4dae7deb4d019de008c540f020b
libpng-debuginfo-1.5.13-8.el7_9.2.ppc64le.rpm SHA-256: a03547f0bd3189669ea3a0b23a9d80acefc79625f7880e35ba65856b0c54e716
libpng-debuginfo-1.5.13-8.el7_9.2.ppc64le.rpm SHA-256: a03547f0bd3189669ea3a0b23a9d80acefc79625f7880e35ba65856b0c54e716
libpng-devel-1.5.13-8.el7_9.2.ppc64le.rpm SHA-256: a6b7ef1c19f4a6699e14d44afb4582fdab2b4b632e41641c8f89d616b40ed6c2
libpng-static-1.5.13-8.el7_9.2.ppc64le.rpm SHA-256: a7ff7ddd0b91d4a9b19ff8343a5e4727a8c6ee0d6c581081779656ecf4d9fb6a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility