libpng 1.6.54 is released with two more security-critical fixes

Cosmin Truta <[email protected]> Tue, 13 Jan 2026 00:31:48 +0200
Newsgroups gmane.comp.graphics.png.announce
Message-ID <CAAoVtZyrGqJt2PLSUQ1bDqi4+9F=6QYpmd894HEZ-mX8LaDGKg@mail.gmail.com>
--===============0232395306444085316==
Content-Type: multipart/alternative; boundary="000000000000739172064838714c"

--000000000000739172064838714c
Content-Type: text/plain; charset="UTF-8"

Dear community of PNG and libpng users,

So I thought I fixed them all...

Not so. libpng-1.6.54 is out, with two more security-sensitive fixes:

*CVE-2026-22695*
https://github.com/pnggroup/libpng/security/advisories/GHSA-mmq5-27w3-rxpp
Many thanks to Petr Simecek, Stanislav Fort and Pavel Kohout for the
discovery, and to Petr Simecek for the report and the fix.

*CVE-2026-22801*
https://github.com/pnggroup/libpng/security/advisories/GHSA-vgjq-8cw5-ggw8

---

In the good old tradition of file authentication, here are the SHA-2-256
checksums of the published archive files. (Note: the "v1.6.54" release
tag is not published *yet* because my GPG key is expired. I will send
another update, later.)

libpng-1.6.54.tar.gz
472db714567391842e410090df5a37e0f5b2ec67148a3007678b0482d2ba5219

libpng-1.6.54.tar.xz
01c9d8a303c941ec2c511c14312a3b1d36cedb41e2f5168ccdaa85d53b887805

lpng1654.7z
ddf203e908dde810d195cf8fb6312def34f6417d24718ccd7cff94ea6e944c6f

lpng1654.zip
fee759f49af6c5e5cf5829dda54c68b9c1d665f42018e13d8ab4aa18bd2a2718

---

Sincerely,
Cosmin

--000000000000739172064838714c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Dear community of PNG and libpng users,</div><div><br=
></div><div>So I thought I fixed them all...</div><div><br></div><div>Not s=
o. libpng-1.6.54 is out, with two more security-sensitive fixes:</div><div>=
<br></div><div><b>CVE-2026-22695</b></div><div><a href=3D"https://github.co=
m/pnggroup/libpng/security/advisories/GHSA-mmq5-27w3-rxpp">https://github.c=
om/pnggroup/libpng/security/advisories/GHSA-mmq5-27w3-rxpp</a></div><div>Ma=
ny thanks to=C2=A0Petr Simecek, Stanislav Fort and Pavel Kohout for the dis=
covery, and to Petr Simecek for the report and the fix.</div><div><br></div=
><div><b>CVE-2026-22801</b></div><div><a href=3D"https://github.com/pnggrou=
p/libpng/security/advisories/GHSA-vgjq-8cw5-ggw8">https://github.com/pnggro=
up/libpng/security/advisories/GHSA-vgjq-8cw5-ggw8</a></div><div><br></div><=
div>---</div><div><br></div><div>In the good old tradition of file authenti=
cation, here are the SHA-2-256 checksums of the published archive files. (N=
ote: the=C2=A0&quot;v1.6.54&quot; release tag=C2=A0is not published *yet* b=
ecause my GPG key is expired. I will send another update, later.)</div><div=
><br></div><div>libpng-1.6.54.tar.gz<br>472db714567391842e410090df5a37e0f5b=
2ec67148a3007678b0482d2ba5219<br><br>libpng-1.6.54.tar.xz<br>01c9d8a303c941=
ec2c511c14312a3b1d36cedb41e2f5168ccdaa85d53b887805<br><br>lpng1654.7z<br>dd=
f203e908dde810d195cf8fb6312def34f6417d24718ccd7cff94ea6e944c6f<br><br>lpng1=
654.zip<br>fee759f49af6c5e5cf5829dda54c68b9c1d665f42018e13d8ab4aa18bd2a2718=
</div><div><br></div><div>---</div><div><br></div><div>Sincerely,</div><div=
>Cosmin</div><div><br></div></div>

--000000000000739172064838714c--


--===============0232395306444085316==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============0232395306444085316==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
png-mng-announce mailing list
png-mng-announce-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/png-mng-announce

--===============0232395306444085316==--