Home / mailingsPDF  

[USN-8639-1] libpng vulnerabilities

Posted on 19 August 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8639-1
August 17, 2026

libpng, libpng1.6 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in libpng.

Software Description:
- libpng1.6: PNG (Portable Network Graphics) file library
- libpng: PNG (Portable Network Graphics) file library

Details:

Patrick Keshishian discovered that libpng incorrectly handled certain
text chunks. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10087)

It was discovered that libpng incorrectly handled certain malformed
images. An attacker could possibly use this issue to cause a denial of
service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-14048)

It was discovered that libpng incorrectly handled memory when freeing
certain images. An attacker could possibly use this issue to cause
a denial of service. This issue only affected Ubuntu 16.04 LTS.
(CVE-2019-7317)

It was discovered that libpng incorrectly handled memory when
processing certain images. An attacker could possibly use this issue
to cause a denial of service, or execute arbitrary code. This issue only
affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS. (CVE-2026-33416)

It was discovered that libpng incorrectly handled certain images. An
attacker could possibly use this issue to cause a denial of service or
execute arbitrary code. This issue only affected Ubuntu 20.04 LTS.
(CVE-2026-33636)

It was discovered that libpng incorrectly handled memory when
processing certain images. An attacker could possibly use this issue
to cause a denial of service or obtain sensitive information. This issue
only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and
Ubuntu 20.04 LTS. (CVE-2026-34757)

Seung Min Shin discovered that libpng incorrectly handled certain
animated images. An attacker could possibly use this issue to cause
libpng to misinterpret image data. This issue only affected Ubuntu
20.04 LTS and Ubuntu 22.04 LTS. (CVE-2026-40930)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
libpng-dev 1.6.37-3ubuntu0.6
libpng-tools 1.6.37-3ubuntu0.6
libpng16-16 1.6.37-3ubuntu0.6

Ubuntu 20.04 LTS
libpng-dev 1.6.37-2ubuntu0.1~esm3
Available with Ubuntu Pro
libpng-tools 1.6.37-2ubuntu0.1~esm3
Available with Ubuntu Pro
libpng16-16 1.6.37-2ubuntu0.1~esm3
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libpng-dev 1.6.34-1ubuntu0.18.04.2+esm3
Available with Ubuntu Pro
libpng-tools 1.6.34-1ubuntu0.18.04.2+esm3
Available with Ubuntu Pro
libpng16-16 1.6.34-1ubuntu0.18.04.2+esm3
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libpng12-0 1.2.54-1ubuntu1.1+esm3
Available with Ubuntu Pro
libpng12-dev 1.2.54-1ubuntu1.1+esm3
Available with Ubuntu Pro
libpng16-16 1.6.20-2ubuntu0.1~esm4
Available with Ubuntu Pro
libpng16-dev 1.6.20-2ubuntu0.1~esm4
Available with Ubuntu Pro
libpng16-devtools 1.6.20-2ubuntu0.1~esm4
Available with Ubuntu Pro
libpng16-tools 1.6.20-2ubuntu0.1~esm4
Available with Ubuntu Pro
libpng3 1.2.54-1ubuntu1.1+esm3
Available with Ubuntu Pro

Ubuntu 14.04 LTS
libpng12-0 1.2.50-1ubuntu2.14.04.3+esm2
Available with Ubuntu Pro
libpng12-dev 1.2.50-1ubuntu2.14.04.3+esm2
Available with Ubuntu Pro
libpng3 1.2.50-1ubuntu2.14.04.3+esm2
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8639-1
CVE-2016-10087, CVE-2018-14048, CVE-2019-7317, CVE-2026-33416,
CVE-2026-33636, CVE-2026-34757, CVE-2026-40930

Package Information:
https://launchpad.net/ubuntu/+source/libpng1.6/1.6.37-3ubuntu0.6

--===============7595530365304396370==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP