Alerts This Week
Warning Icon 1 967
Alerts This Week
Warning Icon 1 967

Oracle Linux 9 libpng Moderate Security Vulnerabilities ELSA-2026-28255

oracle
Calendar Grey June 26, 2026
Oracle Linux Logo Esm H88
Updated libpng packages for Oracle Linux 9 address moderate security flaws. Fixes CVE-2026-33416 and CVE-2026-33636.
The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:

Summary

[2:1.6.37-15.2] - fix CVE-2026-33416: use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE (RHEL-161448) [2:1.6.37-15.1] - fix CVE-2026-33636: out-of-bounds R/W in the palette expansion on ARM Neon (RHEL-161299)

SRPMs

http://oss.oracle.com/ol9/SRPMS-updates/libpng-1.6.37-15.el9_8.2.src.rpm

x86_64

libpng-1.6.37-15.el9_8.2.i686.rpm libpng-1.6.37-15.el9_8.2.x86_64.rpm libpng-devel-1.6.37-15.el9_8.2.i686.rpm libpng-devel-1.6.37-15.el9_8.2.x86_64.rpm

aarch64

libpng-1.6.37-15.el9_8.2.aarch64.rpm libpng-devel-1.6.37-15.el9_8.2.aarch64.rpm

Severity
moderate
Lowest
Low
Medium
High
Critical

Related CVEs: CVE-2026-33416 CVE-2026-33636

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here