Important: mingw-libpng security update
MinGW Windows Libpng library. Security Fix(es): * libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801) * libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695) * libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
MinGW Windows Libpng library. Security Fix(es): * libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801) * libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695) * libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2026:4306
- https://access.redhat.com/security/cve/CVE-2026-22695
- https://access.redhat.com/security/cve/CVE-2026-22801
- https://access.redhat.com/security/cve/CVE-2026-25646
- https://bugzilla.redhat.com/2428824
- https://bugzilla.redhat.com/2428825
- https://bugzilla.redhat.com/2438542
- https://errata.almalinux.org/8/ALSA-2026-4306.html