- Description
- LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- libpng
CVSS 3.1
- Type
- Secondary
- Base score
- 7.1
- Impact score
- 4.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
- Severity
- HIGH
- security-advisories@github.com
- CWE-125
- Hype score
- Not currently trending
🚨 CVE-2025-66293 PATCHED for #Ubuntu. Critical RCE flaw in libpng library demands immediate action. Read more: 👉 https://t.co/8XRcyIqg9B #Security https://t.co/70DrjDcbZR
@Cezar_H_Linux
14 Jan 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
openSUSE releases libpng16 security update fixing multiple buffer overflow issues, including CVE-2025-65018 and CVE-2025-66293. Users should update promptly. #Vulnerability https://t.co/hrg0gN6RsG
@threatcluster
20 Dec 2025
64 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-66293 LIBPNG has an out-of-bounds read in png_image_read_composite https://t.co/3P0dvIRYGx #SecQube #MicrosoftSecurity
@SecQube
12 Dec 2025
20 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-66293 LIBPNG has an out-of-bounds read in png_image_read_composite https://t.co/3P0dvIRYGx #cybersecurity #SecQube
@SecQube
9 Dec 2025
36 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-66293 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of… https://t.co/ROcpYQLuqc
@CVEnew
3 Dec 2025
213 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:libpng:libpng:*:*:*:*:*:*:*:*",
"matchCriteriaId": "98FBE7B9-73DC-483B-87E8-5229792557C3",
"versionEndExcluding": "1.6.52",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]