PNG Vulnerabilities Allow Attackers to Trigger Process Crashes, Leak Sensitive Information
ID: e3cc7f0b-2370-5a07-b053-4fd23889d908
STIX ID: report--e3cc7f0b-2370-5a07-b053-4fd23889d908
Feed Name: cybersecurityNews.com
Two high-severity vulnerabilities were disclosed in libpng: CVE-2026-33416, a use-after-free that can enable heap corruption and potential remote code execution on systems lacking modern mitigations, and CVE-2026-33636, an ARM/AArch64 Neon-optimized palette expansion bug causing out-of-bounds reads/writes that can leak memory and cause crashes; administrators should upgrade to libpng 1.6.56 or 1.8.0 immediately or recompile without hardware optimizations as a temporary workaround.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
