- What: Security update for libpng12
- Impact: Addresses moderate-severity vulnerabilities in image format library
Red Hat Product Errata RHSA-2026:29020 - Security Advisory Issued: 2026-06-24 Updated: 2026-06-24 RHSA-2026:29020 - Security Advisory Overview Updated Packages Synopsis Moderate: libpng12 security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libpng12 is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The libpng12 package provides libpng 1.2, which is the previous version of the libpng library for manipulating PNG (Portable Network Graphics) image format files. This version should be used in case that it is not possible to use the current version of libpng. Security Fix(es): libpng: libpng: Arbitrary code execution due to use-after-free vulnerability (CVE-2026-33416) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2451805 - CVE-2026-33416 libpng: libpng: Arbitrary code execution due to use-after-free vulnerability CVEs CVE-2026-33416 References https://access.redhat.com/security/updates/classification/#moderate Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 SRPM libpng12-1.2.57-5.el8_6.2.src.rpm SHA-256: 40a273d60b6bd2b488adb0f1820ac21bb0e1f13b29e195c0945d97f4498d7b92 x86_64 libpng12-1.2.57-5.el8_6.2.i686.rpm SHA-256: 632dc947fe1546f199d23314aeef2a2c7ee28797f5e037d276faf293b16ad52c libpng12-1.2.57-5.el8_6.2.x86_64.rpm SHA-256: 0b218f1f6ef76c93b5349b51fa2b9e20942b50528bd9b5d712f8b8915b1e1689 libpng12-debuginfo-1.2.57-5.el8_6.2.i686.rpm SHA-256: 588d24a9af367db8af7b18cb84ee183a1aab801977b3f2a7e3ff054ba24f53fe libpng12-debuginfo-1.2.57-5.el8_6.2.x86_64.rpm SHA-256: 98058b6ba1e26045d1766ed08540b3ee886358300ac2c9dc815b0ac38202bd8e libpng12-debugsource-1.2.57-5.el8_6.2.i686.rpm SHA-256: baea8e122fc6d1203d6fd03817f03077858d4e19da2a323f0e07e9cf5972c44a libpng12-debugsource-1.2.57-5.el8_6.2.x86_64.rpm SHA-256: 762435fc9ddfc511db311af89c97fdb157487af77292e8178f27810d00894861 Red Hat Enterprise Linux Server - AUS 8.6 SRPM libpng12-1.2.57-5.el8_6.2.src.rpm SHA-256: 40a273d60b6bd2b488adb0f1820ac21bb0e1f13b29e195c0945d97f4498d7b92 x86_64 libpng12-1.2.57-5.el8_6.2.i686.rpm SHA-256: 632dc947fe1546f199d23314aeef2a2c7ee28797f5e037d276faf293b16ad52c libpng12-1.2.57-5.el8_6.2.x86_64.rpm SHA-256: 0b218f1f6ef76c93b5349b51fa2b9e20942b50528bd9b5d712f8b8915b1e1689 libpng12-debuginfo-1.2.57-5.el8_6.2.i686.rpm SHA-256: 588d24a9af367db8af7b18cb84ee183a1aab801977b3f2a7e3ff054ba24f53fe libpng12-debuginfo-1.2.57-5.el8_6.2.x86_64.rpm SHA-256: 98058b6ba1e26045d1766ed08540b3ee886358300ac2c9dc815b0ac38202bd8e libpng12-debugsource-1.2.57-5.el8_6.2.i686.rpm SHA-256: baea8e122fc6d1203d6fd03817f03077858d4e19da2a323f0e07e9cf5972c44a libpng12-debugsource-1.2.57-5.el8_6.2.x86_64.rpm SHA-256: 762435fc9ddfc511db311af89c97fdb157487af77292e8178f27810d00894861 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .