libpng 1.6.58 released

Cosmin Truta <[email protected]> Thu, 16 Apr 2026 02:37:53 +0300
Newsgroups gmane.comp.graphics.png.announce
Message-ID <CAAoVtZzZOfdqNg7i7Ktkvvkq+2nnVYAMjCQCcUAQjiGo50cVJg@mail.gmail.com>
--===============4520563450906570174==
Content-Type: multipart/alternative; boundary="0000000000001dcfa3064f8835b5"

--0000000000001dcfa3064f8835b5
Content-Type: text/plain; charset="UTF-8"

Earlier this April, I wrote:

> Hello there!
>
> Remember those load-bearing TODO comments from the 1.6.56 announcement?
The ones that said *"Fix this"* for 25 years? Well, fixing them introduced
a new problem. The irony has still not finished writing itself.

I am eager to announce that the irony's pen has struck again!

Last time, in libpng 1.6.57, we fixed a use-after-free regression from the
CVE-2026-33416 de-aliasing work in 1.6.56. This time, in libpng 1.6.58, we
fixed another regression from the same work: the palette sync after
in-place gamma and background transforms was introduced with a guard
condition that was wrong for these transforms. The result: png_get_PLTE
returns stale palette data on indexed-colour images when gamma correction
or background compositing is the sole transform applied. The fix removes
the guard and syncs unconditionally.

If you picked up 1.6.56 or 1.6.57 for the security fixes, you should pick
up 1.6.58 as well. It's a single fix commit, easy to audit.

Many thanks to @ralfjunker for reporting this.

https://github.com/pnggroup/libpng/blob/v1.6.58/ANNOUNCE

---

In the good old tradition of file authentication, here are the SHA-2-256
checksums of the published archive files:

libpng-1.6.58.tar.gz
8c9b05b675ca7301a458df2c2e46f26e1d41ff36b8863f8c33530bc58c2e6225

libpng-1.6.58.tar.xz
28eb403f51f0f7405249132cecfe82ea5c0ef97f1b32c5a65828814ae0d34775

lpng1658.7z
1d19f4e855e620ef9db93842deae338e8075df9f819f8181a82d77a118126260

lpng1658.zip
b32f170855dbbe3e6d9e645af40b538137041773672c3ba3e02db5816c82d376

---

Sincerely,
Cosmin

--0000000000001dcfa3064f8835b5
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr">Earlier this April, I wrote:<br><br><span=
 style=3D"color:rgb(102,102,102)">&gt; Hello there!<br>&gt;<br>&gt; Remembe=
r those load-bearing TODO comments from the 1.6.56 announcement? The ones t=
hat said <i>&quot;Fix this&quot;</i> for 25 years? Well, fixing them introd=
uced a new problem. The irony has still not finished writing itself.</span>=
<br><br>I am eager to announce that the irony&#39;s pen has struck again!<b=
r><br>Last time, in libpng 1.6.57, we fixed a use-after-free regression fro=
m the CVE-2026-33416 de-aliasing work in 1.6.56. This time, in libpng 1.6.5=
8, we fixed another regression from the same work: the palette sync after i=
n-place gamma and background transforms was introduced with a guard conditi=
on that was wrong for these transforms. The result: png_get_PLTE returns st=
ale palette data on indexed-colour images when gamma correction or backgrou=
nd compositing is the sole transform applied. The fix removes the guard and=
 syncs unconditionally.<br><br>If you picked up 1.6.56 or 1.6.57 for the se=
curity fixes, you should pick up 1.6.58 as well. It&#39;s a single fix comm=
it, easy to audit.<br><br>Many thanks to @ralfjunker for reporting this.<br=
><br><a href=3D"https://github.com/pnggroup/libpng/blob/v1.6.58/ANNOUNCE" t=
arget=3D"_blank">https://github.com/pnggroup/libpng/blob/v1.6.58/ANNOUNCE</=
a><br><div><br></div><div>---</div><div><br></div><div>In the good old trad=
ition of file authentication, here are the SHA-2-256 checksums of the publi=
shed archive files:<br><br>libpng-1.6.58.tar.gz<br>8c9b05b675ca7301a458df2c=
2e46f26e1d41ff36b8863f8c33530bc58c2e6225<br><br>libpng-1.6.58.tar.xz<br>28e=
b403f51f0f7405249132cecfe82ea5c0ef97f1b32c5a65828814ae0d34775<br><br>lpng16=
58.7z<br>1d19f4e855e620ef9db93842deae338e8075df9f819f8181a82d77a118126260<b=
r><br>lpng1658.zip<br>b32f170855dbbe3e6d9e645af40b538137041773672c3ba3e02db=
5816c82d376</div><div><br></div><div>---</div><div><br></div><div>Sincerely=
,</div><div>Cosmin</div><div><br></div></div>
</div>

--0000000000001dcfa3064f8835b5--


--===============4520563450906570174==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============4520563450906570174==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
png-mng-announce mailing list
png-mng-announce-5NWGOfrQmneRv+LV9MX5uipxlwaOVQ5f@public.gmane.org
https://lists.sourceforge.net/lists/listinfo/png-mng-announce

--===============4520563450906570174==--