Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <87v77o9i0v.fsf@gentoo.org>
Date: Tue, 29 Sep 2026 16:47:12 +0100
From: Sam James <sam@...too.org>
To: oss-security@...ts.openwall.com
Subject: Re: libpng 1.6.59: Use-after-free vulnerability
 fixed: CVE-2026-46675

Cosmin Truta <ctruta@...il.com> writes:

> Hello, everyone,

Hi Cosmin,

>
> libpng 1.6.59 has been released, fixing a medium-severity
> use-after-free vulnerability in the sequential reader, present since
> libpng 1.6.0. It affects applications that call png_read_end without
> first starting to read the image rows.
>
> Users should either upgrade to libpng 1.6.59 or apply the fix
> described below.
>
> [...]

I can't find a tarball for libpng-1.6.59 in the usual places:
https://sourceforge.net/projects/libpng/files/libpng16/ has no 1.6.59
dir and http://libpng.download/src linked from the README in the repo
has no recent releases.

Is there a plan to make an official tarball available, or to use the
GitHub autogenerated ones going forward? The latter is unfortunate if so
because they're not guaranteed to be stable (and can't be signed, though
libpng releases aren't signed at the moment; was going to file a bug
asking about that).

Cheers!
sam

Download attachment "signature.asc" of type "application/pgp-signature" (419 bytes)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.