FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

png -- Out-of-bounds read

Affected packages
png < 1.6.52

Details

VuXML ID f323f148-d181-11f0-841f-843a4b343614
Discovery 2025-12-03
Entry 2025-12-05

https://github.com/pnggroup/libpng/security/advisories/GHSA-9mpm-9pxh-mg4f reports:

Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management.

References

CVE Name CVE-2025-66293
URL https://cveawg.mitre.org/api/cve/CVE-2025-66293