<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 05:03:46 +0000</lastBuildDate>
    <item>
      <title>ALSA-2026:3031 — Important: libpng15 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2026:3031</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libpng15&lt;/p&gt;
&lt;p&gt;The libpng15 package provides libpng 1.5, an older version of the libpng. library for manipulating PNG (Portable Network Graphics) image format files. This version should be used only if you are unable to use the current version of libpng.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: libpng15&lt;/p&gt;
&lt;p&gt;The libpng15 package provides libpng 1.5, an older version of the libpng. library for manipulating PNG (Portable Network Graphics) image format files. This version should be used only if you are unable to use the current version of libpng.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* libpng: LIBPNG has a heap buffer overflow in png_set_quantize (CVE-2026-25646)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2026:3031</guid>
    </item>
    <item>
      <title>bdu:2026-01774</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2026-01774</link>
      <description>bdu:2026-01774</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2026-01774</guid>
    </item>
    <item>
      <title>BELL-CVE-2026-25646</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2026-25646</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libpng, Alpaquita:25: libpng, Alpaquita:stream: libpng, BellSoft Hardened Containers:23: libpng, BellSoft Hardened Containers:25: libpng, BellSoft Hardened Containers:stream: libpng&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: libpng, Alpaquita:25: libpng, Alpaquita:stream: libpng, BellSoft Hardened Containers:23: libpng, BellSoft Hardened Containers:25: libpng, BellSoft Hardened Containers:stream: libpng&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2026-25646</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0199 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Certaines d'entre elles permettent à un attaq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</link>
      <description>certfr-2026-avi-0199</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0199</guid>
    </item>
    <item>
      <title>Withdrawn: CLEANSTART-2026-AO11810 — Netty is an asynchronous, event-driven network application framework</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-ao11810</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-zookeeper&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-zookeeper package. Netty is an asynchronous, event-driven network application framework. See references for individual vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: apache-zookeeper&lt;/p&gt;
&lt;p&gt;Multiple security vulnerabilities affect the apache-zookeeper package. Netty is an asynchronous, event-driven network application framework. See references for individual vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-ao11810</guid>
    </item>
    <item>
      <title>EUVD-2026-362285</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362285</link>
      <description>EUVD-2026-362285</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362285</guid>
    </item>
    <item>
      <title>fkie_cve-2026-25646</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-25646</link>
      <description>&lt;p&gt;LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user&amp;#39;s display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user&amp;#39;s display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-25646</guid>
    </item>
    <item>
      <title>OESA-2026-1476 — libpng security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1476</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: libpng, openEuler:20.03-LTS-SP4: libpng, openEuler:22.03-LTS-SP4: libpng, openEuler:24.03-LTS: libpng, openEuler:24.03-LTS-SP1: libpng, openEuler:24.03-LTS-SP2: libpng&lt;/p&gt;
&lt;p&gt;The libpng package contains libraries used by other programs for reading and writing PNG format files. The PNG format was designed as a replacement for GIF and, to a lesser extent, TIFF, with many improvements and extensions and lack of patent problems.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user&amp;amp;apos;s display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.(CVE-2026-25646)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: libpng, openEuler:20.03-LTS-SP4: libpng, openEuler:22.03-LTS-SP4: libpng, openEuler:24.03-LTS: libpng, openEuler:24.03-LTS-SP1: libpng, openEuler:24.03-LTS-SP2: libpng&lt;/p&gt;
&lt;p&gt;The libpng package contains libraries used by other programs for reading and writing PNG format files. The PNG format was designed as a replacement for GIF and, to a lesser extent, TIFF, with many improvements and extensions and lack of patent problems.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user&amp;amp;apos;s display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.(CVE-2026-25646)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1476</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10188-1 — libpng16-16-1.6.55-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10188-1</link>
      <description>&lt;p&gt;libpng16-16-1.6.55-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;libpng16-16-1.6.55-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10188-1</guid>
    </item>
    <item>
      <title>RHSA-2026:10097 — Red Hat Security Advisory: OpenShift Container Platform 4.16.60 bug fix and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:10097</link>
      <description>&lt;p&gt;grub2: Missing unregister call for gettext command may lead to use-after-free libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing libpng: LIBPNG has a heap buffer overflow in png_set_quantize vim: Vim: Arbitrary code execution via &amp;#39;helpfile&amp;#39; option processing vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file vim: Vim: Arbitrary code execution via command injection in glob() function&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;grub2: Missing unregister call for gettext command may lead to use-after-free libarchive: Infinite Loop Denial of Service in RAR5 Decompression via archive_read_data() in libarchive libarchive: libarchive: Information disclosure via heap out-of-bounds read in RAR archive processing libarchive: libarchive: Arbitrary code execution via integer overflow in ISO9660 image processing libpng: LIBPNG has a heap buffer overflow in png_set_quantize vim: Vim: Arbitrary code execution via &amp;#39;helpfile&amp;#39; option processing vim: Vim: Arbitrary code execution via OS command injection in the netrw plugin vim: Vim: Denial of service and information disclosure via crafted swap file vim: Vim: Arbitrary code execution via command injection in glob() function&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:10097</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:0583-1 — Security update for libpng16</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:0583-1</link>
      <description>&lt;p&gt;Security update for libpng16&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for libpng16&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:0583-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-25646</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25646</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libpng, Ubuntu:Pro:16.04:LTS: libpng, Ubuntu:Pro:16.04:LTS: libpng1.6, Ubuntu:Pro:18.04:LTS: libpng1.6, Ubuntu:Pro:20.04:LTS: libpng1.6, Ubuntu:22.04:LTS: libpng1.6, Ubuntu:24.04:LTS: libpng1.6, Ubuntu:25.10: libpng1.6, Ubuntu:26.04:LTS: libpng1.6&lt;/p&gt;
&lt;p&gt;LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user&amp;#39;s display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: libpng, Ubuntu:Pro:16.04:LTS: libpng, Ubuntu:Pro:16.04:LTS: libpng1.6, Ubuntu:Pro:18.04:LTS: libpng1.6, Ubuntu:Pro:20.04:LTS: libpng1.6, Ubuntu:22.04:LTS: libpng1.6, Ubuntu:24.04:LTS: libpng1.6, Ubuntu:25.10: libpng1.6, Ubuntu:26.04:LTS: libpng1.6&lt;/p&gt;
&lt;p&gt;LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.55, an out-of-bounds read vulnerability exists in the png_set_quantize() API function. When the function is called with no histogram and the number of colors in the palette is more than twice the maximum supported by the user&amp;#39;s display, certain palettes will cause the function to enter into an infinite loop that reads past the end of an internal heap-allocated buffer. The images that trigger this vulnerability are valid per the PNG specification. This vulnerability is fixed in 1.6.55.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-25646</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-0353 — libpng: Schwachstelle ermöglicht Codeausführung</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0353</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libpng ausnutzen, um möglicherweise beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in libpng ausnutzen, um möglicherweise beliebigen Code auszuführen, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-0353</guid>
    </item>
  </channel>
</rss>
