Security update for libpng12
This update for libpng12 fixes the following issues: Update to version 1.2.59 (jsc#PED-16191). - CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754). - CVE-2026-34757: use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` can lead to corrupted chunk data and potential heap information disclosure (bsc#1261957).
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libpng12 fixes the following issues: Update to version 1.2.59 (jsc#PED-16191). - CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754). - CVE-2026-34757: use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` can lead to corrupted chunk data and potential heap information disclosure (bsc#1261957).
05 / REFERENCES