logo

The 30-Year Glitch: RCE and ARM Exploits Uncovered in libpng Reference Library

ID: 31eb2884-e018-5a87-980d-893366bf2b77

STIX ID: report--31eb2884-e018-5a87-980d-893366bf2b77

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers disclosed two serious libpng flaws: an ARM/AArch64 Neon palette-expansion out-of-bounds bug that can crash or leak heap data (CVE-2026-33636), and a longstanding use-after-free via shared buffers between png_struct and png_info that can enable remote code execution with crafted, standards-compliant PNGs (CVE-2026-33416). Patches are available in libpng v1.6.56 and v1.8.0; short-term mitigations include disabling ARM Neon optimizations at compile time and auditing png_free_data usage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.