Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. # Security update for libpng16 Announcement ID: SUSE-SU-2026:2057-1 Release Date: 2026-05-25T14:04:25Z Rating: moderate References: * bsc#1261957 Cross-References: * CVE-2026-34757 CVSS scores: * CVE-2026-34757 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34757 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for libpng16 fixes the following issue: * CVE-2026-34757: information disclosure and data corruption due to use-after- free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` (bsc#1261957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2057=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2057=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2057=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2057=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2057=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2057=1 * SUSE Linux EnterpriseMicro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2057=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libpng16-16-debuginfo-1.6.34-150000.3.25.1 * libpng16-debugsource-1.6.34-150000.3.25.1 * libpng16-16-1.6.34-150000.3.25.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libpng16-16-debuginfo-1.6.34-150000.3.25.1 * libpng16-debugsource-1.6.34-150000.3.25.1 * libpng16-16-1.6.34-150000.3.25.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libpng16-16-debuginfo-1.6.34-150000.3.25.1 * libpng16-debugsource-1.6.34-150000.3.25.1 * libpng16-16-1.6.34-150000.3.25.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libpng16-16-debuginfo-1.6.34-150000.3.25.1 * libpng16-debugsource-1.6.34-150000.3.25.1 * libpng16-16-1.6.34-150000.3.25.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libpng16-16-debuginfo-1.6.34-150000.3.25.1 * libpng16-debugsource-1.6.34-150000.3.25.1 * libpng16-16-1.6.34-150000.3.25.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * libpng16-16-debuginfo-1.6.34-150000.3.25.1 * libpng16-debugsource-1.6.34-150000.3.25.1 * libpng16-16-1.6.34-150000.3.25.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * libpng16-16-debuginfo-1.6.34-150000.3.25.1 * libpng16-debugsource-1.6.34-150000.3.25.1 * libpng16-16-1.6.34-150000.3.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34757.html * https://bugzilla.suse.com/show_bug.cgi?id=1261957 . Update released for libpng16 addressing information disclosure and data corruption vulnerabilities with moderate severity.. libpng16 update information disclosure data corruption. . Severity: moderate. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libpng16 Announcement ID: SUSE-SU-2026:1601-1 Release Date: 2026-04-24T11:46:17Z Rating: moderate References: * bsc#1261957 Cross-References: * CVE-2026-34757 CVSS scores: * CVE-2026-34757 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34757 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libpng16 fixes the following issue: * CVE-2026-34757: information disclosure and data corruption due to use-after- free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` (bsc#1261957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1601=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpng16-devel-1.6.8-15.24.1 * libpng16-16-1.6.8-15.24.1 * libpng16-16-32bit-1.6.8-15.24.1 * libpng16-16-debuginfo-32bit-1.6.8-15.24.1 * libpng16-debugsource-1.6.8-15.24.1 * libpng16-16-debuginfo-1.6.8-15.24.1 * libpng16-compat-devel-1.6.8-15.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34757.html * https://bugzilla.suse.com/show_bug.cgi?id=1261957 . Update patch released addressing moderate risk vulnerability in libpng16 for SUSE Linux, fixing data corruption issues.. SUSE libpng16 data corruptionvulnerability patch. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libpng16 Announcement ID: SUSE-SU-2026:1602-1 Release Date: 2026-04-24T11:46:32Z Rating: moderate References: * bsc#1261957 Cross-References: * CVE-2026-34757 CVSS scores: * CVE-2026-34757 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34757 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libpng16 fixes the following issue: * CVE-2026-34757: information disclosure and data corruption due to use-after- free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` (bsc#1261957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-1602=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1602=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * libpng16-compat-devel-1.6.40-150600.3.20.1 * libpng16-tools-debuginfo-1.6.40-150600.3.20.1 * libpng16-devel-1.6.40-150600.3.20.1 * libpng16-16-1.6.40-150600.3.20.1 * libpng16-tools-1.6.40-150600.3.20.1 * libpng16-debugsource-1.6.40-150600.3.20.1 * libpng16-16-debuginfo-1.6.40-150600.3.20.1 * openSUSE Leap 15.6 (x86_64) * libpng16-16-32bit-1.6.40-150600.3.20.1 * libpng16-16-32bit-debuginfo-1.6.40-150600.3.20.1 *libpng16-devel-32bit-1.6.40-150600.3.20.1 * libpng16-compat-devel-32bit-1.6.40-150600.3.20.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpng16-compat-devel-64bit-1.6.40-150600.3.20.1 * libpng16-16-64bit-1.6.40-150600.3.20.1 * libpng16-16-64bit-debuginfo-1.6.40-150600.3.20.1 * libpng16-devel-64bit-1.6.40-150600.3.20.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libpng16-compat-devel-1.6.40-150600.3.20.1 * libpng16-devel-1.6.40-150600.3.20.1 * libpng16-16-1.6.40-150600.3.20.1 * libpng16-debugsource-1.6.40-150600.3.20.1 * libpng16-16-debuginfo-1.6.40-150600.3.20.1 * Basesystem Module 15-SP7 (x86_64) * libpng16-16-32bit-1.6.40-150600.3.20.1 * libpng16-16-32bit-debuginfo-1.6.40-150600.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34757.html * https://bugzilla.suse.com/show_bug.cgi?id=1261957 . Update for SUSE libpng16 resolves information disclosure and data corruption issue. Ensure your system is secure today!. libpng16 update, SUSE security advisory, information disclosure fix, linux patch. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libpng16 Announcement ID: SUSE-SU-2026:21251-1 Release Date: 2026-04-21T08:57:43Z Rating: moderate References: * bsc#1261957 Cross-References: * CVE-2026-34757 CVSS scores: * CVE-2026-34757 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34757 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libpng16 fixes the following issue: * CVE-2026-34757: libpng: Information disclosure and data corruption via use- after-free vulnerability (bsc#1261957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-680=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libpng16-debugsource-1.6.43-5.1 * libpng16-16-debuginfo-1.6.43-5.1 * libpng16-16-1.6.43-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34757.html * https://bugzilla.suse.com/show_bug.cgi?id=1261957 . SUSE Linux Micro 6.0 updates libpng16 for moderate info disclosure and corruption fix. Install patch now to secure system.. SUSE Linux Micro, libpng16, security patch, moderate risk, information disclosure. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libpng16 Announcement ID: SUSE-SU-2026:21262-1 Release Date: 2026-04-21T08:33:03Z Rating: moderate References: * bsc#1261957 Cross-References: * CVE-2026-34757 CVSS scores: * CVE-2026-34757 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34757 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libpng16 fixes the following issue: * CVE-2026-34757: libpng: Information disclosure and data corruption via use- after-free vulnerability (bsc#1261957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-499=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libpng16-16-1.6.43-slfo.1.1_5.1 * libpng16-16-debuginfo-1.6.43-slfo.1.1_5.1 * libpng16-debugsource-1.6.43-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34757.html * https://bugzilla.suse.com/show_bug.cgi?id=1261957 . Update for libpng16 addresses moderate risk info disclosure and data corruption vulnerability. Learn more.. libpng16 update,suse security,information disclosure fix,data corruption patch. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # Security update for libpng16 Announcement ID: SUSE-SU-2026:21239-1 Release Date: 2026-04-21T10:12:43Z Rating: moderate References: * bsc#1261957 Cross-References: * CVE-2026-34757 CVSS scores: * CVE-2026-34757 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34757 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for libpng16 fixes the following issue: * CVE-2026-34757: libpng: Information disclosure and data corruption via use- after-free vulnerability (bsc#1261957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-603=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libpng16-16-1.6.44-160000.7.1 * libpng16-debugsource-1.6.44-160000.7.1 * libpng16-16-debuginfo-1.6.44-160000.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34757.html * https://bugzilla.suse.com/show_bug.cgi?id=1261957 . Update resolves moderate severity issue in libpng16 with potential information disclosure and data corruption risk.. libpng16 security update, SUSE Linux vulnerability, data corruption risk, moderate severity security advisory. . LinuxSecurity.com Team
An update that solves two vulnerabilities can now be installed.. # Security update for libpng16 Announcement ID: SUSE-SU-2026:21138-1 Release Date: 2026-04-07T11:57:38Z Rating: important References: * bsc#1260754 * bsc#1260755 Cross-References: * CVE-2026-33416 * CVE-2026-33636 CVSS scores: * CVE-2026-33416 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-33416 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-33416 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-33636 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-33636 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-33636 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libpng16 fixes the following issues: * CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754). * CVE-2026-33636: out-of-bounds read/write in the palette expansion on ARM Neon can lead to information leak and crashes (bsc#1260755). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-480=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-480=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libpng16-devel-1.6.44-160000.6.1 * libpng16-compat-devel-1.6.44-160000.6.1 * libpng16-16-1.6.44-160000.6.1 *libpng16-tools-debuginfo-1.6.44-160000.6.1 * libpng16-tools-1.6.44-160000.6.1 * libpng16-debugsource-1.6.44-160000.6.1 * libpng16-16-debuginfo-1.6.44-160000.6.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libpng16-devel-x86-64-v3-1.6.44-160000.6.1 * libpng16-compat-devel-x86-64-v3-1.6.44-160000.6.1 * libpng16-16-x86-64-v3-debuginfo-1.6.44-160000.6.1 * libpng16-16-x86-64-v3-1.6.44-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libpng16-devel-1.6.44-160000.6.1 * libpng16-compat-devel-1.6.44-160000.6.1 * libpng16-16-1.6.44-160000.6.1 * libpng16-tools-debuginfo-1.6.44-160000.6.1 * libpng16-tools-1.6.44-160000.6.1 * libpng16-debugsource-1.6.44-160000.6.1 * libpng16-16-debuginfo-1.6.44-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libpng16-devel-x86-64-v3-1.6.44-160000.6.1 * libpng16-compat-devel-x86-64-v3-1.6.44-160000.6.1 * libpng16-16-x86-64-v3-debuginfo-1.6.44-160000.6.1 * libpng16-16-x86-64-v3-1.6.44-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33416.html * https://www.suse.com/security/cve/CVE-2026-33636.html * https://bugzilla.suse.com/show_bug.cgi?id=1260754 * https://bugzilla.suse.com/show_bug.cgi?id=1260755 . Update for libpng16 addresses important vulnerabilities with risks of code execution and information leaks. Patch now.. libpng16 security update, SUSE Linux vulnerabilities, important security advisory, information leak risk, arbitrary code execution. . Severity: Important. LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # libpng16-16-1.6.57-1.1 on GA media Announcement ID: openSUSE-SU-2026:10564-1 Rating: moderate Cross-References: * CVE-2026-34757 CVSS scores: * CVE-2026-34757 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the libpng16-16-1.6.57-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * libpng16-16 1.6.57-1.1 * libpng16-16-32bit 1.6.57-1.1 * libpng16-16-x86-64-v3 1.6.57-1.1 * libpng16-compat-devel 1.6.57-1.1 * libpng16-compat-devel-32bit 1.6.57-1.1 * libpng16-compat-devel-x86-64-v3 1.6.57-1.1 * libpng16-devel 1.6.57-1.1 * libpng16-devel-32bit 1.6.57-1.1 * libpng16-devel-x86-64-v3 1.6.57-1.1 * libpng16-tools 1.6.57-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34757.html . Moderate security alert for openSUSE, addressing a crucial issue in libpng16 vulnerability affecting package versions.. openSUSE, libpng16, security update. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.