Security update for libpng12
This update for libpng12 fixes the following issues: Update to version 1.2.59 (jsc#PED-16191). Security issues : - CVE-2017-12652: missing chunk length check can lead to sensitive information disclosure, data corruption or crash (bsc#1141493). - CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754). - CVE-2026-34757: use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` can lead to corrupted chunk data and potential heap information disclosure (bsc#1261957).
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libpng12 fixes the following issues: Update to version 1.2.59 (jsc#PED-16191). Security issues : - CVE-2017-12652: missing chunk length check can lead to sensitive information disclosure, data corruption or crash (bsc#1141493). - CVE-2026-33416: use-after-free via pointer aliasing in `png_set_tRNS` and `png_set_PLTE` can lead to arbitrary code execution (bsc#1260754). - CVE-2026-34757: use-after-free in `png_set_PLTE`, `png_set_tRNS` and `png_set_hIST` can lead to corrupted chunk data and potential heap information disclosure (bsc#1261957).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1141493
- https://bugzilla.suse.com/1260754
- https://bugzilla.suse.com/1261957
- https://www.suse.com/security/cve/CVE-2017-12652
- https://www.suse.com/security/cve/CVE-2026-33416
- https://www.suse.com/security/cve/CVE-2026-34757
- https://www.suse.com/support/update/announcement/2026/suse-su-20261716-1/