FlawAtlas
Search the atlas
SUSE-SU-2026:1716-1 Not scored

Security update for libpng12

This update for libpng12 fixes the following issues: Update to version 1.2.59 (jsc#PED-16191). Security issues : - CVE-2017-12652: missing chunk length check can lead to sensitive information disclosure, data corruption or crash (bsc#1141493). - CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754). - CVE-2026-34757: use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` can lead to corrupted chunk data and potential heap information disclosure (bsc#1261957).

Exploit probability Not scored
Published May 6, 2026
Required by Not available
Last source change May 7, 2026

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1716-1

This update for libpng12 fixes the following issues: Update to version 1.2.59 (jsc#PED-16191). Security issues : - CVE-2017-12652: missing chunk length check can lead to sensitive information disclosure, data corruption or crash (bsc#1141493). - CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754). - CVE-2026-34757: use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` can lead to corrupted chunk data and potential heap information disclosure (bsc#1261957).

View original source

05 / REFERENCES

Further evidence