libpng 1.6.54 is released with two more security-critical fixes
Cosmin Truta <[email protected]> Tue, 13 Jan 2026 00:31:48 +0200
| Newsgroups | gmane.comp.graphics.png.announce |
|---|---|
| Message-ID | <CAAoVtZyrGqJt2PLSUQ1bDqi4+9F=6QYpmd894HEZ-mX8LaDGKg@mail.gmail.com> |
--===============0232395306444085316== Content-Type: multipart/alternative; boundary="000000000000739172064838714c" --000000000000739172064838714c Content-Type: text/plain; charset="UTF-8" Dear community of PNG and libpng users, So I thought I fixed them all... Not so. libpng-1.6.54 is out, with two more security-sensitive fixes: *CVE-2026-22695* https://github.com/pnggroup/libpng/security/advisories/GHSA-mmq5-27w3-rxpp Many thanks to Petr Simecek, Stanislav Fort and Pavel Kohout for the discovery, and to Petr Simecek for the report and the fix. *CVE-2026-22801* https://github.com/pnggroup/libpng/security/advisories/GHSA-vgjq-8cw5-ggw8 --- In the good old tradition of file authentication, here are the SHA-2-256 checksums of the published archive files. (Note: the "v1.6.54" release tag is not published *yet* because my GPG key is expired. I will send another update, later.) libpng-1.6.54.tar.gz 472db714567391842e410090df5a37e0f5b2ec67148a3007678b0482d2ba5219 libpng-1.6.54.tar.xz 01c9d8a303c941ec2c511c14312a3b1d36cedb41e2f5168ccdaa85d53b887805 lpng1654.7z ddf203e908dde810d195cf8fb6312def34f6417d24718ccd7cff94ea6e944c6f lpng1654.zip fee759f49af6c5e5cf5829dda54c68b9c1d665f42018e13d8ab4aa18bd2a2718 --- Sincerely, Cosmin --000000000000739172064838714c Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div>Dear community of PNG and libpng users,</div><div><br= ></div><div>So I thought I fixed them all...</div><div><br></div><div>Not s= o. libpng-1.6.54 is out, with two more security-sensitive fixes:</div><div>= <br></div><div><b>CVE-2026-22695</b></div><div><a href=3D"https://github.co= m/pnggroup/libpng/security/advisories/GHSA-mmq5-27w3-rxpp">https://github.c= om/pnggroup/libpng/security/advisories/GHSA-mmq5-27w3-rxpp</a></div><div>Ma= ny thanks to=C2=A0Petr Simecek, Stanislav Fort and Pavel Kohout for the dis= covery, and to Petr Simecek for the report and the fix.</div><div><br></div= ><div><b>CVE-2026-22801</b></div><div><a href=3D"https://github.com/pnggrou= p/libpng/security/advisories/GHSA-vgjq-8cw5-ggw8">https://github.com/pnggro= up/libpng/security/advisories/GHSA-vgjq-8cw5-ggw8</a></div><div><br></div><= div>---</div><div><br></div><div>In the good old tradition of file authenti= cation, here are the SHA-2-256 checksums of the published archive files. (N= ote: the=C2=A0"v1.6.54" release tag=C2=A0is not published *yet* b= ecause my GPG key is expired. I will send another update, later.)</div><div= ><br></div><div>libpng-1.6.54.tar.gz<br>472db714567391842e410090df5a37e0f5b= 2ec67148a3007678b0482d2ba5219<br><br>libpng-1.6.54.tar.xz<br>01c9d8a303c941= ec2c511c14312a3b1d36cedb41e2f5168ccdaa85d53b887805<br><br>lpng1654.7z<br>dd= f203e908dde810d195cf8fb6312def34f6417d24718ccd7cff94ea6e944c6f<br><br>lpng1= 654.zip<br>fee759f49af6c5e5cf5829dda54c68b9c1d665f42018e13d8ab4aa18bd2a2718= </div><div><br></div><div>---</div><div><br></div><div>Sincerely,</div><div= >Cosmin</div><div><br></div></div> --000000000000739172064838714c-- --===============0232395306444085316== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============0232395306444085316== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ png-mng-announce mailing list png-mng-announce-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/png-mng-announce --===============0232395306444085316==--