Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Debian 11 DLA-4521-1 libpng1.6 Critical Exploit DDoS CVE-2026-33416

debian lts
Calendar Grey April 2, 2026
Dist Debian Esm H88
Two critical vulnerabilities found in libpng leading to denial of service and possible code execution, update recommended.
Two security vulnerabilities were discovered in libpng, a library implementing an interface for reading and writing PNG (Portable Network Graphics) files, which could result in den...

Summary

CVE-2026-33416

Use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE`,
potentially allowing arbitrary code execution

CVE-2026-33636

Out-of-bounds read/write in the palette expansion on ARM Neon, potentially
causing a crash (DoS)

For Debian 11 bullseye, these problems have been fixed in version
1.6.37-3+deb11u3.

We recommend that you upgrade your libpng1.6 packages.

For the detailed security status of libpng1.6 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/libpng1.6

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



Severity
critical
Lowest
Low
Medium
High
Critical

Package: libpng1.6
Version: 1.6.37-3+deb11u3
CVE ID: CVE-2026-33416 CVE-2026-33636
Debian Bug: 1132012 1132013

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here