Skip to main content
Early Access
— Mondoo Vulnerability Intelligence is currently in preview.
Vulnerability Intelligence
Login
Get Demo
Back to search
ELSA-2026-0237
UNKNOWN
ELSA-2026-0237: libpng security update (IMPORTANT)
Published Jan 7, 2026
Modified 1 weeks ago
Fix available
Details
[2:1.6.40-8.1]
CVE-2025-64720: buffer overflow (RHEL-131422)
CVE-2025-65018: heap buffer overflow (RHEL-131435)
CVE-2025-66293: out-of-bounds read in png_image_read_composite (RHEL-133212)
Affected Packages
OracleLinux:10
libpng
Fixed in:
2:1.6.40-8.el10_1.1
OracleLinux:10
libpng-devel
Fixed in:
2:1.6.40-8.el10_1.1
Related
CVE-2025-64720
CVE-2025-65018
CVE-2025-66293
Ecosystems
OracleLinux 10
Timeline
Published
Jan 7, 2026
Modified
Jan 7, 2026
ELSA-2026-0237 | Mondoo Vulnerability Intelligence