Security update for libpng16
This update for libpng16 fixes the following issues: - CVE-2025-28162: memory leaks when running `pngimage` (bsc#1257364). - CVE-2025-28164: memory leaks when running `pngimage` (bsc#1257365). - CVE-2026-22695: heap buffer over-read in png_image_finish_read (bsc#1256525). - CVE-2026-22801: integer truncation causing heap buffer over-read in png_image_write_* (bsc#1256526). - CVE-2026-25646: heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for libpng16 fixes the following issues: - CVE-2025-28162: memory leaks when running `pngimage` (bsc#1257364). - CVE-2025-28164: memory leaks when running `pngimage` (bsc#1257365). - CVE-2026-22695: heap buffer over-read in png_image_finish_read (bsc#1256525). - CVE-2026-22801: integer truncation causing heap buffer over-read in png_image_write_* (bsc#1256526). - CVE-2026-25646: heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1256525
- https://bugzilla.suse.com/1256526
- https://bugzilla.suse.com/1257364
- https://bugzilla.suse.com/1257365
- https://bugzilla.suse.com/1258020
- https://www.suse.com/security/cve/CVE-2025-28162
- https://www.suse.com/security/cve/CVE-2025-28164
- https://www.suse.com/security/cve/CVE-2026-22695
- https://www.suse.com/security/cve/CVE-2026-22801
- https://www.suse.com/security/cve/CVE-2026-25646
- https://www.suse.com/support/update/announcement/2026/suse-su-202620523-1/