CVE-2025-28164

Published: January 29, 2026Last modified: February 2, 2026

Description

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.

Severity score breakdown

ParameterValue
Base score5.5
Attack VectorLOCAL
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityNONE
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Notes

The earliest version on 25-LTS is after the vulnerable range.

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSlibpngFixed (1.6.53-r0)
StreamlibpngFixed (1.6.47-r0)
Hardened Containers23 LTSlibpngFixed (1.6.53-r0)
StreamlibpngFixed (1.6.47-r0)

References

ON THIS PAGE