Description:
LIBPNG has a heap buffer over-read in png_image_read_direct_scaled
(regression from CVE-2025-65018 fix). (CVE-2026-22695)
LIBPNG has an integer truncation causing heap buffer over-read in
png_image_write_*. (CVE-2026-22801)
- https://bugs.mageia.org/show_bug.cgi?id=34986
- https://www.openwall.com/lists/oss-security/2026/01/12/7
- https://www.cve.org/CVERecord?id=CVE-2026-22695
- https://www.cve.org/CVERecord?id=CVE-2026-22801
- 9/core/libpng-1.6.38-1.3.mga9
Get the latest Linux and open source security news straight to your inbox.