Posted by Cosmin Truta on Sep 28 Hello, everyone, libpng 1.6.59 has been released, fixing a medium-severity use-after-free vulnerability in the sequential reader, present since libpng 1.6.0. It affects applications that call png_read_end without first starting to read the image rows. Users should either upgrade to libpng 1.6.59 or apply the fix described below. === CVE-2026-46675 === Use-after-free of zlib input in png_read_end after incomplete zTXt, iTXt or iCCP...
libpng 1.6.59: Use-after-free vulnerability fixed: CVE-2026-46675
About this summary. This is a short, independently written summary of an article first published by oss-security. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/oss-sec/2026/q3/977
Source attribution: headline and facts are from oss-security (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.



