Home / mailings [USN-8639-1] libpng vulnerabilities
Posted on 19 August 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8639-1
August 17, 2026
libpng, libpng1.6 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in libpng.
Software Description:
- libpng1.6: PNG (Portable Network Graphics) file library
- libpng: PNG (Portable Network Graphics) file library
Details:
Patrick Keshishian discovered that libpng incorrectly handled certain
text chunks. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10087)
It was discovered that libpng incorrectly handled certain malformed
images. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-14048)
It was discovered that libpng incorrectly handled memory when freeing
certain images. An attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-7317)
It was discovered that libpng incorrectly handled memory when
processing certain images. An attacker could possibly use this issue
to cause a denial of service, or execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS. (CVE-2026-33416)
It was discovered that libpng incorrectly handled certain images. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 20.04 LTS.
(CVE-2026-33636)
It was discovered that libpng incorrectly handled memory when
processing certain images. An attacker could possibly use this issue
to cause a denial of service or obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS. (CVE-2026-34757)
Seung Min Shin discovered that libpng incorrectly handled certain
animated images. An attacker could possibly use this issue to cause
libpng to misinterpret image data. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2026-40930)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 22.04 LTS
libpng-dev 1.6.37-3ubuntu0.6
libpng-tools 1.6.37-3ubuntu0.6
libpng16-16 1.6.37-3ubuntu0.6
Ubuntu 20.04 LTS
libpng-dev 1.6.37-2ubuntu0.1~esm3
Available with Ubuntu Pro
libpng-tools 1.6.37-2ubuntu0.1~esm3
Available with Ubuntu Pro
libpng16-16 1.6.37-2ubuntu0.1~esm3
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libpng-dev 1.6.34-1ubuntu0.18.04.2+esm3
Available with Ubuntu Pro
libpng-tools 1.6.34-1ubuntu0.18.04.2+esm3
Available with Ubuntu Pro
libpng16-16 1.6.34-1ubuntu0.18.04.2+esm3
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libpng12-0 1.2.54-1ubuntu1.1+esm3
Available with Ubuntu Pro
libpng12-dev 1.2.54-1ubuntu1.1+esm3
Available with Ubuntu Pro
libpng16-16 1.6.20-2ubuntu0.1~esm4
Available with Ubuntu Pro
libpng16-dev 1.6.20-2ubuntu0.1~esm4
Available with Ubuntu Pro
libpng16-devtools 1.6.20-2ubuntu0.1~esm4
Available with Ubuntu Pro
libpng16-tools 1.6.20-2ubuntu0.1~esm4
Available with Ubuntu Pro
libpng3 1.2.54-1ubuntu1.1+esm3
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libpng12-0 1.2.50-1ubuntu2.14.04.3+esm2
Available with Ubuntu Pro
libpng12-dev 1.2.50-1ubuntu2.14.04.3+esm2
Available with Ubuntu Pro
libpng3 1.2.50-1ubuntu2.14.04.3+esm2
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8639-1
CVE-2016-10087, CVE-2018-14048, CVE-2019-7317, CVE-2026-33416,
CVE-2026-33636, CVE-2026-34757, CVE-2026-40930
Package Information:
https://launchpad.net/ubuntu/+source/libpng1.6/1.6.37-3ubuntu0.6
--===============7595530365304396370==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
