<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T16:14:47.851663+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2026:3405</id>
    <title>ALSA-2026:3405 — Important: libpng security update</title>
    <updated>2026-10-02T16:14:48.575148+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: libpng, AlmaLinux:9: libpng-devel</p>
<p>The libpng packages contain a library of functions for creating and manipulating Portable Network Graphics (PNG) image format files.</p>
<p>Security Fix(es):</p>
<p>* libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API (CVE-2026-22801)
  * libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read (CVE-2026-22695)
  * libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2026:3405"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-04960</id>
    <title>bdu:2026-04960</title>
    <updated>2026-10-02T16:14:48.575258+00:00</updated>
    <content>bdu:2026-04960</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-04960"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2026-22801</id>
    <title>BELL-CVE-2026-22801</title>
    <updated>2026-10-02T16:14:48.575284+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: libpng, Alpaquita:25: libpng, Alpaquita:stream: libpng, BellSoft Hardened Containers:23: libpng, BellSoft Hardened Containers:25: libpng, BellSoft Hardened Containers:stream: libpng</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2026-22801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</id>
    <title>certfr-2026-avi-0199 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
    <updated>2026-10-02T16:14:48.575313+00:00</updated>
    <content>certfr-2026-avi-0199</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-af52025</id>
    <title>Withdrawn: CLEANSTART-2026-AF52025 — In libexpat before 2</title>
    <updated>2026-10-02T16:14:48.575330+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Withdrawn by the publisher.</strong></p>
<p><strong>Affected:</strong> CleanStart: apache-zookeeper</p>
<p>Multiple security vulnerabilities affect the apache-zookeeper package. In libexpat before 2. See references for individual vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-af52025"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-265580</id>
    <title>EUVD-2026-265580</title>
    <updated>2026-10-02T16:14:48.575351+00:00</updated>
    <content>EUVD-2026-265580</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-265580"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-22801</id>
    <title>fkie_cve-2026-22801</title>
    <updated>2026-10-02T16:14:48.575362+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-22801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2026-22801</id>
    <title>msrc_CVE-2026-22801 — LIBPNG has an integer truncation causing heap buffer over-read in png_image_write_*</title>
    <updated>2026-10-02T16:14:48.575386+00:00</updated>
    <content>msrc_CVE-2026-22801</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2026-22801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1205</id>
    <title>OESA-2026-1205 — libpng security update</title>
    <updated>2026-10-02T16:14:48.575402+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS: libpng, openEuler:24.03-LTS-SP1: libpng, openEuler:24.03-LTS-SP2: libpng, openEuler:24.03-LTS-SP3: libpng, openEuler:20.03-LTS-SP4: libpng, openEuler:22.03-LTS-SP4: libpng</p>
<p>The libpng package contains libraries used by other programs for reading and writing PNG format files.
The PNG format was designed as a replacement for GIF and, to a lesser extent, TIFF,
with many improvements and extensions and lack of patent problems.

Security Fix(es):</p>
<p>LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.51 to 1.6.53, there is a heap buffer over-read in the libpng simplified API function png_image_finish_read when processing interlaced 16-bit PNGs with 8-bit output format and non-minimal row stride. This is a regression introduced by the fix for CVE-2025-65018. This vulnerability is fixed in 1.6.54.(CVE-2026-22695)</p>
<p>LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.(CVE-2026-22801)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1205"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10060-1</id>
    <title>openSUSE-SU-2026:10060-1 — libpng16-16-1.6.54-1.1 on GA media</title>
    <updated>2026-10-02T16:14:48.575440+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libpng16-16-1.6.54-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10060-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:12274</id>
    <title>RHSA-2026:12274 — Red Hat Security Advisory: OpenShift Container Platform 4.12.88 bug fix and security update</title>
    <updated>2026-10-02T16:14:48.575457+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing libpng: libpng: Denial of service and information disclosure via heap buffer over-read in png_image_finish_read libpng: libpng: Information disclosure and denial of service via integer truncation in simplified write API libpng: LIBPNG has a heap buffer overflow in png_set_quantize vim: Vim: Arbitrary code execution via 'helpfile' option processing vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file vim: Vim: Arbitrary code execution via command injection in glob() function</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:12274"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2026:20127-1</id>
    <title>SUSE-SU-2026:20127-1 — Security update for libpng16</title>
    <updated>2026-10-02T16:14:48.575488+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for libpng16</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2026:20127-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22801</id>
    <title>UBUNTU-CVE-2026-22801</title>
    <updated>2026-10-02T16:14:48.575503+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: libpng1.6, Ubuntu:Pro:20.04:LTS: libpng1.6, Ubuntu:22.04:LTS: libpng1.6, Ubuntu:24.04:LTS: libpng1.6, Ubuntu:25.10: libpng1.6, Ubuntu:26.04:LTS: libpng1.6</p>
<p>LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.6.26 to 1.6.53, there is an integer truncation in the libpng simplified write API functions png_write_image_16bit and png_write_image_8bit causes heap buffer over-read when the caller provides a negative row stride (for bottom-up image layouts) or a stride exceeding 65535 bytes. The bug was introduced in libpng 1.6.26 (October 2016) by casts added to silence compiler warnings on 16-bit systems. This vulnerability is fixed in 1.6.54.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-22801"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0068</id>
    <title>WID-SEC-W-2026-0068 — libpng (API-Funktionen): Mehrere Schwachstellen ermöglichen DoS und Offenlegung von Informationen</title>
    <updated>2026-10-02T16:14:48.575531+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in libpng ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0068"/>
  </entry>
</feed>
