Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 471
Alerts This Week
Warning Icon 1 471

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 221 articles for you...
100

SUSE Linux 12 SP5 Important Libpng15 Heap Overflow Advisory 2026-2878-1

An update that solves one vulnerability can now be installed.. # Security update for libpng15 Announcement ID: SUSE-SU-2026:2878-1 Release Date: 2026-07-13T09:27:39Z Rating: important References: * bsc#1258020 Cross-References: * CVE-2026-25646 CVSS scores: * CVE-2026-25646 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-25646 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-25646 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25646 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-25646 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libpng15 fixes the following issue * CVE-2026-25646: heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2878=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2878=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpng15-15-debuginfo-1.5.30-10.16.1 * libpng15-debugsource-1.5.30-10.16.1 *libpng15-15-1.5.30-10.16.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpng15-15-debuginfo-1.5.30-10.16.1 * libpng15-debugsource-1.5.30-10.16.1 * libpng15-15-1.5.30-10.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25646.html * https://bugzilla.suse.com/show_bug.cgi?id=1258020 . Critical update for libpng15 addresses a buffer overflow issue, enhancing security for SUSE users. Install promptly to mitigate risks.. libpng buffer overflow SUSE security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 13, 2026 Important SuSE
217

Oracle Linux 9 libpng Moderate Security Vulnerabilities ELSA-2026-28255

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-28255 http://linux.oracle.com/errata/ELSA-2026-28255.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: libpng-1.6.37-15.el9_8.2.i686.rpm libpng-1.6.37-15.el9_8.2.x86_64.rpm libpng-devel-1.6.37-15.el9_8.2.i686.rpm libpng-devel-1.6.37-15.el9_8.2.x86_64.rpm aarch64: libpng-1.6.37-15.el9_8.2.aarch64.rpm libpng-devel-1.6.37-15.el9_8.2.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/libpng-1.6.37-15.el9_8.2.src.rpm Related CVEs: CVE-2026-33416 CVE-2026-33636 Description of changes: [2:1.6.37-15.2] - fix CVE-2026-33416: use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE (RHEL-161448) [2:1.6.37-15.1] - fix CVE-2026-33636: out-of-bounds R/W in the palette expansion on ARM Neon (RHEL-161299) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updated libpng packages for Oracle Linux 9 address moderate security flaws. Fixes CVE-2026-33416 and CVE-2026-33636.. Oracle Linux libpng security fix. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 moderate Oracle
217

Oracle Linux 8 ELSA-2026-29898 libpng Moderate Use-After-Free Fix

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-29898 http://linux.oracle.com/errata/ELSA-2026-29898.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libpng-1.6.34-11.el8_10.i686.rpm libpng-1.6.34-11.el8_10.x86_64.rpm libpng-devel-1.6.34-11.el8_10.i686.rpm libpng-devel-1.6.34-11.el8_10.x86_64.rpm aarch64: libpng-1.6.34-11.el8_10.aarch64.rpm libpng-devel-1.6.34-11.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/libpng-1.6.34-11.el8_10.src.rpm Related CVEs: CVE-2026-33416 Description of changes: [2:1.6.37-11] - fix CVE-2026-33416: use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE (RHEL-161344) _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Updated libpng packages for Oracle Linux 8 address use-after-free issue. Install the latest update to ensure security.. Oracle Linux, libpng updates, security fix, moderate severity, use-after-free issue. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 moderate Oracle
219

Rocky Linux 8 libpng Moderate Code Execution Vulnerability RLSA-2026-29898

Moderate: libpng security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:29898", "synopsis": "Moderate: libpng security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libpng.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.\n\nSecurity Fix(es):\n\n* libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2451805", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451805", "description": ""}], "cves": [{"name": "CVE-2026-33416", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33416", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-825"}], "references": [], "publishedAt": "2026-06-26T00:00:49.542580Z", "rpms": {"Rocky Linux 8": {"nvras": ["libpng-2:1.6.34-11.el8_10.aarch64.rpm", "libpng-2:1.6.34-11.el8_10.i686.rpm", "libpng-2:1.6.34-11.el8_10.src.rpm", "libpng-2:1.6.34-11.el8_10.x86_64.rpm", "libpng-debuginfo-2:1.6.34-11.el8_10.aarch64.rpm", "libpng-debuginfo-2:1.6.34-11.el8_10.i686.rpm", "libpng-debuginfo-2:1.6.34-11.el8_10.x86_64.rpm", "libpng-debugsource-2:1.6.34-11.el8_10.aarch64.rpm", "libpng-debugsource-2:1.6.34-11.el8_10.i686.rpm", "libpng-debugsource-2:1.6.34-11.el8_10.x86_64.rpm", "libpng-devel-2:1.6.34-11.el8_10.aarch64.rpm", "libpng-devel-2:1.6.34-11.el8_10.i686.rpm", "libpng-devel-2:1.6.34-11.el8_10.x86_64.rpm","libpng-devel-debuginfo-2:1.6.34-11.el8_10.aarch64.rpm", "libpng-devel-debuginfo-2:1.6.34-11.el8_10.i686.rpm", "libpng-devel-debuginfo-2:1.6.34-11.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Keep your Rocky Linux system secure with this moderate libpng update addressing a significant code execution issue due to a vulnerability.. Rocky Linux libpng update, arbitrary code execution risk, security patches Rocky Linux. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 26, 2026 moderate Rocky Linux
219

Rocky Linux 10 RLSA-2026-28233 libpng Moderate Arbitrary Code Execution

Moderate: libpng security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28233", "synopsis": "Moderate: libpng security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libpng.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.\n\nSecurity Fix(es):\n\n* libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416)\n\n* libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2451805", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451805", "description": ""}, {"ticket": "2451819", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451819", "description": ""}], "cves": [{"name": "CVE-2026-33416", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33416", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-825"}, {"name": "CVE-2026-33636", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33636", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H", "cvss3BaseScore": "7.6", "cwe": "CWE-124"}], "references": [], "publishedAt": "2026-06-24T12:05:09.232192Z", "rpms": {"Rocky Linux 10": {"nvras": ["libpng-debugsource-2:1.6.40-11.el10_2.1.aarch64.rpm","libpng-devel-debuginfo-2:1.6.40-11.el10_2.1.ppc64le.rpm", "libpng-devel-2:1.6.40-11.el10_2.1.ppc64le.rpm", "libpng-2:1.6.40-11.el10_2.1.aarch64.rpm", "libpng-2:1.6.40-11.el10_2.1.ppc64le.rpm", "libpng-debugsource-2:1.6.40-11.el10_2.1.x86_64.rpm", "libpng-debugsource-2:1.6.40-11.el10_2.1.s390x.rpm", "libpng-devel-2:1.6.40-11.el10_2.1.aarch64.rpm", "libpng-debuginfo-2:1.6.40-11.el10_2.1.s390x.rpm", "libpng-devel-2:1.6.40-11.el10_2.1.x86_64.rpm", "libpng-debuginfo-2:1.6.40-11.el10_2.1.aarch64.rpm", "libpng-debuginfo-2:1.6.40-11.el10_2.1.x86_64.rpm", "libpng-devel-debuginfo-2:1.6.40-11.el10_2.1.aarch64.rpm", "libpng-devel-2:1.6.40-11.el10_2.1.s390x.rpm", "libpng-2:1.6.40-11.el10_2.1.x86_64.rpm", "libpng-2:1.6.40-11.el10_2.1.s390x.rpm", "libpng-devel-debuginfo-2:1.6.40-11.el10_2.1.s390x.rpm", "libpng-2:1.6.40-11.el10_2.1.src.rpm", "libpng-debugsource-2:1.6.40-11.el10_2.1.ppc64le.rpm", "libpng-devel-debuginfo-2:1.6.40-11.el10_2.1.x86_64.rpm", "libpng-debuginfo-2:1.6.40-11.el10_2.1.ppc64le.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A moderate security advisory for Rocky Linux provides essential updates on libpng vulnerabilities and potential threats.. libpng update, Rocky Linux security, arbitrary code execution, information disclosure, security advisory. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 24, 2026 moderate Rocky Linux
219

Rocky Linux libpng Security Update RLSA-2026-28255 Addresses CVE-2026-33416

Moderate: libpng security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:28255", "synopsis": "Moderate: libpng security update", "severity": "SEVERITY_MODERATE", "topic": "An update is available for libpng.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.\n\nSecurity Fix(es):\n\n* libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416)\n\n* libpng: libpng: Information disclosure and denial of service via out-of-bounds read/write in Neon palette expansion (CVE-2026-33636)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2451805", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451805", "description": ""}, {"ticket": "2451819", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2451819", "description": ""}], "cves": [{"name": "CVE-2026-33416", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33416", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-825"}, {"name": "CVE-2026-33636", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33636", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H", "cvss3BaseScore": "7.6", "cwe": "CWE-124"}], "references": [], "publishedAt": "2026-06-24T12:03:26.635873Z", "rpms": {"Rocky Linux 9": {"nvras": ["libpng-2:1.6.37-15.el9_8.2.aarch64.rpm", "libpng-2:1.6.37-15.el9_8.2.i686.rpm","libpng-2:1.6.37-15.el9_8.2.ppc64le.rpm", "libpng-2:1.6.37-15.el9_8.2.s390x.rpm", "libpng-2:1.6.37-15.el9_8.2.src.rpm", "libpng-2:1.6.37-15.el9_8.2.x86_64.rpm", "libpng-debuginfo-2:1.6.37-15.el9_8.2.aarch64.rpm", "libpng-debuginfo-2:1.6.37-15.el9_8.2.i686.rpm", "libpng-debuginfo-2:1.6.37-15.el9_8.2.ppc64le.rpm", "libpng-debuginfo-2:1.6.37-15.el9_8.2.s390x.rpm", "libpng-debuginfo-2:1.6.37-15.el9_8.2.x86_64.rpm", "libpng-debugsource-2:1.6.37-15.el9_8.2.aarch64.rpm", "libpng-debugsource-2:1.6.37-15.el9_8.2.i686.rpm", "libpng-debugsource-2:1.6.37-15.el9_8.2.ppc64le.rpm", "libpng-debugsource-2:1.6.37-15.el9_8.2.s390x.rpm", "libpng-debugsource-2:1.6.37-15.el9_8.2.x86_64.rpm", "libpng-devel-2:1.6.37-15.el9_8.2.aarch64.rpm", "libpng-devel-2:1.6.37-15.el9_8.2.i686.rpm", "libpng-devel-2:1.6.37-15.el9_8.2.ppc64le.rpm", "libpng-devel-2:1.6.37-15.el9_8.2.s390x.rpm", "libpng-devel-2:1.6.37-15.el9_8.2.x86_64.rpm", "libpng-devel-debuginfo-2:1.6.37-15.el9_8.2.aarch64.rpm", "libpng-devel-debuginfo-2:1.6.37-15.el9_8.2.i686.rpm", "libpng-devel-debuginfo-2:1.6.37-15.el9_8.2.ppc64le.rpm", "libpng-devel-debuginfo-2:1.6.37-15.el9_8.2.s390x.rpm", "libpng-devel-debuginfo-2:1.6.37-15.el9_8.2.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Urgent libpng security update with moderate severity addressing denial of service and arbitrary code execution issues on Rocky Linux.. libpng security, Rocky Linux update, moderate severity patch, DoS fix, arbitrary code execution. . Severity: moderate. LinuxSecurity.com Team

Calendar%202 Jun 24, 2026 moderate Rocky Linux
203

Mageia 9 libpng Important Heap Disclosure CVE-2026-40930

Security update. Publication date: 13 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0205.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-40930 Description: LIBPNG has a use-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure. (CVE-2026-34757) Chunk smuggling in push-mode APNG parser via unconsumed chunk body. (CVE-2026-40930) References: - https://bugs.mageia.org/show_bug.cgi?id=35542 - https://www.openwall.com/lists/oss-security/2026/04/09/2 - https://lists.debian.org/debian-security-announce/2026/msg00174.html - https://www.openwall.com/lists/oss-security/2026/05/15/21 - https://github.com/pnggroup/libpng/security/advisories/GHSA-c4v6-gxrq-6g2x - https://www.cve.org/CVERecord?id=CVE-2026-40930 SRPMS: - 9/core/libpng-1.6.38-1.6.mga9 . Security update for libpng addressing use-after-free and heap disclosure risks in Mageia 9 with CVE-2026-40930.. libpng update, Mageia security, heap corruption, APNG vulnerability, libpng security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 12, 2026 Important Mageia
89

Fedora 43 libpng Addresses Medium Severity Memory Bug CVE-2026-34757

updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-a109a9ac2c 2026-06-02 01:10:43.197462+00:00 -------------------------------------------------------------------------------- Name : libpng Product : Fedora 43 Version : 1.6.58 Release : 1.fc43 URL : http://www.libpng.org/pub/png/ Summary : A library of functions for manipulating PNG image format files Description : The libpng package contains a library of functions for creating and manipulating PNG (Portable Network Graphics) image format files. PNG is a bit-mapped graphics format similar to the GIF format. PNG was created to replace the GIF format, since GIF uses a patented data compression algorithm. Libpng should be installed if you need to manipulate PNG format image files. -------------------------------------------------------------------------------- Update Information: updated to 1.6.58 1.6.58 is released with a fix for a simple correctness bug (not a security issue) this time: png_get_PLTE() returns stale palette data when either gamma correction or alpha-compositing is the only transform applied. Like the issues addressed in the previous release, this bug was a regression introduced in the fix for CVE-2026-33416 in 1.6.56. 1.6.57 is released with fixes for the following security vulnerability: CVE-2026-34757 (medium severity): Use-after-free memory bug in the chunk setter API. The hIST variant has existed since version 1.0.9, but the PLTE and tRNS ones are regressions introduced in the fix for CVE-2026-33416 in 1.6.56(oops). -------------------------------------------------------------------------------- ChangeLog: * Thu May 21 2026 Michal Hlavinka - 2:1.6.58-1 - updated to 1.6.58 (#2456815) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2460625 - CVE-2026-22020 libpng: OpenJDK: Update LibPNG (Oracle CPU 2026-04) [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2460625 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-a109a9ac2c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Fix for medium severity memory bug in libpng 1.6.58 for Fedora 43 addresses regressions and improves functionality.. libpng update, Fedora security advisory, medium severity fix, memory issue, libpng 1.6.58. . Severity: Medium. LinuxSecurity.com Team

Calendar%202 Jun 02, 2026 Medium Fedora
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":75,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":25,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200