CVE-2025-28162

Published: January 29, 2026Last modified: February 2, 2026

Description

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Notes

The earliest version on 25-LTS is after the vulnerable range.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibpngFixed (1.6.53-r0)
StreamlibpngFixed (1.6.47-r0)
Hardened Containers23 LTSlibpngFixed (1.6.53-r0)
StreamlibpngFixed (1.6.47-r0)

References

ON THIS PAGE