Updated: 2026-03-05 03:25:31.707242
Description:
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_read when processing 16-bit interlaced PNGs with 8-bit output format. Attacker-crafted interlaced PNG files cause heap writes beyond allocated buffer bounds. This issue has been patched in version 1.6.51.
| Links | NIST | CIRCL | RHEL | Ubuntu |
| Severity | Score | |
|---|---|---|
| CVSS Version 2.x | NONE | 0.0 |
| CVSS Version 3.x | HIGH | 7.1 |
| OS name | Project name | Version | Score | Severity | Status | Errata | Last updated | Statement |
|---|---|---|---|---|---|---|---|---|
| AlmaLinux 9.2 ESU | libpng | 1.6.37 | 7.1 | HIGH | Released | CLSA-2026:1768394334 | 2026-01-14 16:33:44 | |
| AlmaLinux 9.2 ESU | java-17-openjdk | 17.0.9.0.9 | 7.1 | HIGH | Not Vulnerable | 2026-02-16 23:26:36 | ||
| AlmaLinux 9.2 ESU | java-1.8.0-openjdk | 1.8.0 | 7.1 | HIGH | Not Vulnerable | 2026-02-16 23:26:30 | ||
| CentOS 7 ELS | libpng | 1.5.13 | 7.1 | HIGH | Not Vulnerable | 2026-02-16 23:02:09 | Not affected: CVE-2025-65018 targets libpng 1.6.0–1.6.50 via the simplified API function png_image... | |
| CentOS 8.4 ELS | java-1.8.0-openjdk | 1.8.0 | 7.1 | HIGH | Not Vulnerable | 2026-01-27 14:57:56 | Not vulnerable. CVE-2025-65018 is a libpng flaw in png_image_finish_read; the java-1.8.0-openjdk bui... | |
| CentOS 8.5 ELS | java-1.8.0-openjdk | 1.8.0 | 7.1 | HIGH | Not Vulnerable | 2026-01-29 11:54:36 | Not vulnerable. CVE-2025-65018 is a libpng flaw in png_image_finish_read; the java-1.8.0-openjdk bui... | |
| CentOS Stream 8 ELS | java-1.8.0-openjdk | 1.8.0 | 7.1 | HIGH | Not Vulnerable | 2026-01-27 14:57:57 | Not vulnerable. CVE-2025-65018 is a libpng flaw in png_image_finish_read; the java-1.8.0-openjdk bui... | |
| Oracle Linux 7 ELS | java-1.8.0-openjdk | 1.8.0 | 7.1 | HIGH | In Testing | 2026-03-03 20:58:46 | ||
| Oracle Linux 7 ELS | libpng | 1.5.13 | 7.1 | HIGH | Not Vulnerable | 2026-02-16 23:02:09 | ||
| TuxCare 9.6 ESU | java-21-openjdk | 21.0.9.0.10 | 7.1 | HIGH | Released | CLSA-2026:1771408532 | 2026-02-18 18:34:32 |