LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
History

Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Libpng
Libpng libpng
Vendors & Products Libpng
Libpng libpng

Thu, 04 Dec 2025 02:30:00 +0000

Type Values Removed Values Added
References

Thu, 04 Dec 2025 01:30:00 +0000

Type Values Removed Values Added
References

Thu, 04 Dec 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 03 Dec 2025 23:30:00 +0000

Type Values Removed Values Added
References

Wed, 03 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 03 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
Description LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
Title LIBPNG has an out-of-bounds read in png_image_read_composite
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-12-03T20:33:57.086Z

Updated: 2025-12-04T01:31:47.574Z

Reserved: 2025-11-26T23:11:46.392Z

Link: CVE-2025-66293

cve-icon Vulnrichment

Updated: 2025-12-03T23:03:19.452Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-12-03T21:15:53.060

Modified: 2025-12-04T17:15:08.283

Link: CVE-2025-66293

cve-icon Redhat

Severity : Important

Publid Date: 2025-12-03T20:33:57Z

Links: CVE-2025-66293 - Bugzilla