LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.
References
| Link | Resource |
|---|---|
| https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a | Patch |
| https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc | Patch |
| https://github.com/pnggroup/libpng/issues/836 | Exploit Issue Tracking Mitigation |
| https://github.com/pnggroup/libpng/issues/837 | Exploit Issue Tracking Mitigation |
| https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645 | Mitigation Patch Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2026/05/msg00017.html | Mailing List Third Party Advisory |
Configurations
History
13 May 2026, 23:07
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/pnggroup/libpng/commit/398cbe3df03f4e11bb031e07f416dfdde3684e8a - Patch | |
| References | () https://github.com/pnggroup/libpng/commit/55d20aaa322c9274491cda82c5cd4f99b48c6bcc - Patch | |
| References | () https://github.com/pnggroup/libpng/issues/836 - Exploit, Issue Tracking, Mitigation | |
| References | () https://github.com/pnggroup/libpng/issues/837 - Exploit, Issue Tracking, Mitigation | |
| References | () https://github.com/pnggroup/libpng/security/advisories/GHSA-6fr7-g8h7-v645 - Mitigation, Patch, Vendor Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2026/05/msg00017.html - Mailing List, Third Party Advisory | |
| First Time |
Libpng libpng
Debian debian Linux Libpng Debian |
|
| CPE | cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
09 May 2026, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
09 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-09 15:16
Updated : 2026-05-13 23:07
NVD link : CVE-2026-34757
Mitre link : CVE-2026-34757
CVE.ORG link : CVE-2026-34757
JSON object : View
Products Affected
debian
- debian_linux
libpng
- libpng
CWE
CWE-416
Use After Free
