Executive brief
libpng is a widely used software library for reading and processing PNG image files. A vulnerability in how the library handles image color reduction could allow a specially crafted image to cause a system crash or potentially allow an attacker to access sensitive information. This affects any application that uses libpng to process images, such as web browsers, image viewers, and document processors.
Technical details
A logic error exists in the png_set_quantize() API (formerly png_set_dither()) within libpng. When the function is called without a histogram and the palette size exceeds twice the display's maximum supported colors, a mismatch between current and original palette indices occurs during color pruning. This causes the search bound (max_d) to increment beyond the 769-element heap-allocated 'hash' table, resulting in an infinite loop and out-of-bounds reads/writes. The vulnerability is reachable via network vectors if an application processes untrusted PNGs using the low-level API. The issue is fixed in version 1.6.55 by ensuring original indices are correctly tracked via palette_to_index.
Affected products
- pnggroup libpng < 1.6.55
Timeline
- 2026-02-09: disclosed: Vulnerability disclosed on oss-security mailing list
- 2026-02-10: advisory: GitHub and NVD advisories published
- 2026-02-10: patched: libpng 1.6.55 released
References
- https://github.com/pnggroup/libpng/commit/01d03b8453eb30ade759cd45c707e5a1c7277d88
- https://github.com/pnggroup/libpng/security/advisories/GHSA-g8hp-mq4h-rqm3
- http://www.openwall.com/lists/oss-security/2026/02/09/7
- https://access.redhat.com/errata/RHSA-2026:10097
- https://access.redhat.com/errata/RHSA-2026:12274
- https://access.redhat.com/errata/RHSA-2026:14773
- https://access.redhat.com/errata/RHSA-2026:15087