USN-7963-1 Unknown

USN-7963-1: libpng vulnerabilities

Canonical (Ubuntu) Released: January 14, 2026 Updated: January 15, 2026 Restart Required

Description

It was discovered that the libpng simplified API incorrectly processed palette PNG images with partial transparency and gamma correction. If a user or automated system were tricked into opening a specially crafted PNG file, an attacker could use this issue to cause libpng to crash, resulting in a denial of service. (CVE-2025-66293) Petr Simecek, Stanislav Fort and Pavel Kohout discovered that the libpng simplified API incorrectly processed interlaced 16-bit PNGs with 8-bit output format and non-minimal row strides. If a user or automated system were tricked into opening a specially crafted PNG file, an attacker could use this issue to cause libpng to crash, resulting in a denial of service. (CVE-2026-22695) Cosmin Truta discovered that the libpng simplified API incorrectly handled invalid row strides. If a user or automated system were tricked into opening a specially crafted PNG file, an attacker could use this issue to cause libpng to crash, resulting in a denial of service. (CVE-2026-22801)

Fixed Vulnerabilities 3

CVE-2025-66293 N/A 0.0 ⚠️ KEV fixed
Dec 03, 2025

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an…

CVE-2026-22801 N/A 0.0 ⚠️ KEV fixed
Jan 12, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53,…

CVE-2026-22695 N/A 0.0 ⚠️ KEV fixed
Jan 12, 2026

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.51 to 1.6.53,…

Quick Info

Patch ID: USN-7963-1
Vendor: Canonical (Ubuntu)
Severity: Unknown
CVEs Fixed: 3
Restart: Required

Additional Info

action:
usn id: USN-7963-1
summary: Several security issues were fixed in libpng.
usn number: 7963-1
instructions: In general, a standard system update will make all the necessary changes.

Share