libpng 1.6.58 released
Cosmin Truta <[email protected]> Thu, 16 Apr 2026 02:37:53 +0300
| Newsgroups | gmane.comp.graphics.png.announce |
|---|---|
| Message-ID | <CAAoVtZzZOfdqNg7i7Ktkvvkq+2nnVYAMjCQCcUAQjiGo50cVJg@mail.gmail.com> |
--===============4520563450906570174== Content-Type: multipart/alternative; boundary="0000000000001dcfa3064f8835b5" --0000000000001dcfa3064f8835b5 Content-Type: text/plain; charset="UTF-8" Earlier this April, I wrote: > Hello there! > > Remember those load-bearing TODO comments from the 1.6.56 announcement? The ones that said *"Fix this"* for 25 years? Well, fixing them introduced a new problem. The irony has still not finished writing itself. I am eager to announce that the irony's pen has struck again! Last time, in libpng 1.6.57, we fixed a use-after-free regression from the CVE-2026-33416 de-aliasing work in 1.6.56. This time, in libpng 1.6.58, we fixed another regression from the same work: the palette sync after in-place gamma and background transforms was introduced with a guard condition that was wrong for these transforms. The result: png_get_PLTE returns stale palette data on indexed-colour images when gamma correction or background compositing is the sole transform applied. The fix removes the guard and syncs unconditionally. If you picked up 1.6.56 or 1.6.57 for the security fixes, you should pick up 1.6.58 as well. It's a single fix commit, easy to audit. Many thanks to @ralfjunker for reporting this. https://github.com/pnggroup/libpng/blob/v1.6.58/ANNOUNCE --- In the good old tradition of file authentication, here are the SHA-2-256 checksums of the published archive files: libpng-1.6.58.tar.gz 8c9b05b675ca7301a458df2c2e46f26e1d41ff36b8863f8c33530bc58c2e6225 libpng-1.6.58.tar.xz 28eb403f51f0f7405249132cecfe82ea5c0ef97f1b32c5a65828814ae0d34775 lpng1658.7z 1d19f4e855e620ef9db93842deae338e8075df9f819f8181a82d77a118126260 lpng1658.zip b32f170855dbbe3e6d9e645af40b538137041773672c3ba3e02db5816c82d376 --- Sincerely, Cosmin --0000000000001dcfa3064f8835b5 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr">Earlier this April, I wrote:<br><br><span= style=3D"color:rgb(102,102,102)">> Hello there!<br>><br>> Remembe= r those load-bearing TODO comments from the 1.6.56 announcement? The ones t= hat said <i>"Fix this"</i> for 25 years? Well, fixing them introd= uced a new problem. The irony has still not finished writing itself.</span>= <br><br>I am eager to announce that the irony's pen has struck again!<b= r><br>Last time, in libpng 1.6.57, we fixed a use-after-free regression fro= m the CVE-2026-33416 de-aliasing work in 1.6.56. This time, in libpng 1.6.5= 8, we fixed another regression from the same work: the palette sync after i= n-place gamma and background transforms was introduced with a guard conditi= on that was wrong for these transforms. The result: png_get_PLTE returns st= ale palette data on indexed-colour images when gamma correction or backgrou= nd compositing is the sole transform applied. The fix removes the guard and= syncs unconditionally.<br><br>If you picked up 1.6.56 or 1.6.57 for the se= curity fixes, you should pick up 1.6.58 as well. It's a single fix comm= it, easy to audit.<br><br>Many thanks to @ralfjunker for reporting this.<br= ><br><a href=3D"https://github.com/pnggroup/libpng/blob/v1.6.58/ANNOUNCE" t= arget=3D"_blank">https://github.com/pnggroup/libpng/blob/v1.6.58/ANNOUNCE</= a><br><div><br></div><div>---</div><div><br></div><div>In the good old trad= ition of file authentication, here are the SHA-2-256 checksums of the publi= shed archive files:<br><br>libpng-1.6.58.tar.gz<br>8c9b05b675ca7301a458df2c= 2e46f26e1d41ff36b8863f8c33530bc58c2e6225<br><br>libpng-1.6.58.tar.xz<br>28e= b403f51f0f7405249132cecfe82ea5c0ef97f1b32c5a65828814ae0d34775<br><br>lpng16= 58.7z<br>1d19f4e855e620ef9db93842deae338e8075df9f819f8181a82d77a118126260<b= r><br>lpng1658.zip<br>b32f170855dbbe3e6d9e645af40b538137041773672c3ba3e02db= 5816c82d376</div><div><br></div><div>---</div><div><br></div><div>Sincerely= ,</div><div>Cosmin</div><div><br></div></div> </div> --0000000000001dcfa3064f8835b5-- --===============4520563450906570174== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============4520563450906570174== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ png-mng-announce mailing list png-mng-announce-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org https://lists.sourceforge.net/lists/listinfo/png-mng-announce --===============4520563450906570174==--