Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

SUSE 2026 0596-1 libpng16 Important Heap Buffer Overflow

suse
Calendar Grey February 23, 2026
Dist Suse Esm H88
SUSE Linux security advisory for libpng16 resolves important memory leaks and buffer issues. Action required.
An update that solves five vulnerabilities can now be installed.

Summary

## This update for libpng16 fixes the following issues: * CVE-2025-28162: memory leaks when running `pngimage` (bsc#1257364). * CVE-2025-28164: memory leaks when running `pngimage` (bsc#1257365). * CVE-2026-22695: heap buffer over-read in png_image_finish_read (bsc#1256525). * CVE-2026-22801: integer truncation causing heap buffer over-read in png_image_write_* (bsc#1256526). * CVE-2026-25646: heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-596=1

References

* bsc#1256525

* bsc#1256526

* bsc#1257364

* bsc#1257365

* bsc#1258020

Cross-

* CVE-2025-28162

* CVE-2025-28164

* CVE-2026-22695

* CVE-2026-22801

* CVE-2026-25646

CVSS scores:

* CVE-2025-28162 ( SUSE ): 4.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2025-28162 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

* CVE-2025-28162 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2025-28164 ( SUSE ): 4.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

* CVE-2025-28164 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

* CVE-2025-28164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

* CVE-2026-22695 ( SUSE ): 6.8

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0596-1
Release Date: 2026-02-23T15:57:59Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here