Bug 34799 - libpng new security issue CVE-2025-66293
Summary: libpng new security issue CVE-2025-66293
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-12-04 12:05 CET by Nicolas Salguero
Modified: 2025-12-08 19:37 CET (History)
3 users (show)

See Also:
Source RPM: libpng-1.6.38-1.1.mga9.src.rpm
CVE: CVE-2025-66293
Status comment:


Attachments

Description Nicolas Salguero 2025-12-04 12:05:37 CET
Reference: https://www.openwall.com/lists/oss-security/2025/12/03/5
Nicolas Salguero 2025-12-04 13:05:46 CET

Source RPM: (none) => libpng-1.6.51-2.mga10.src.rpm, libpng-1.6.38-1.1.mga9.src.rpm
Status comment: (none) => Fixed upstream in 1.6.52 and patches available from upstream
Whiteboard: (none) => MGA9TOO
CVE: (none) => CVE-2025-66293

Comment 1 Nicolas Salguero 2025-12-04 13:53:27 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

LIBPNG has an out-of-bounds read in png_image_read_composite. (CVE-2025-66293)

References:
https://www.openwall.com/lists/oss-security/2025/12/03/5
========================

Updated packages in core/updates_testing:
========================
lib(64)png-devel-1.6.38-1.2.mga9
lib(64)png16_16-1.6.38-1.2.mga9

from SRPM:
libpng-1.6.38-1.2.mga9.src.rpm

Status: NEW => ASSIGNED
Version: Cauldron => 9
Status comment: Fixed upstream in 1.6.52 and patches available from upstream => (none)
Whiteboard: MGA9TOO => (none)
Assignee: bugsquad => qa-bugs
Source RPM: libpng-1.6.51-2.mga10.src.rpm, libpng-1.6.38-1.1.mga9.src.rpm => libpng-1.6.38-1.1.mga9.src.rpm

Comment 2 Thomas Andrews 2025-12-04 17:41:40 CET
MGA9-64 Plasma, i5-7500, Nvidia Quadro K620 graphics. No installation issues.

Used Image Magick commands to convert a png image to jpg, and a different image from jpg to png, then used Gwenview to display each. No issues noted.

Looks good to me.

CC: (none) => andrewsfarm
Whiteboard: (none) => MGA9-64-OK

katnatek 2025-12-04 20:02:27 CET

Keywords: (none) => advisory

Comment 3 Dan Fandrich 2025-12-05 23:45:37 CET
Does libpng12 need to be patched as well? The CVE says "Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API…" which implies that.

CC: (none) => dan

Comment 4 Nicolas Salguero 2025-12-06 07:19:08 CET
Hi,

If you follow the thread from the link given above, the answer is that none of the CVEs fixed in version 1.6.51 nor in 1.6.52 affect 1.2.

Best regards,
Comment 5 Thomas Andrews 2025-12-07 13:52:43 CET
Validating.

CC: (none) => sysadmin-bugs
Keywords: (none) => validated_update

Comment 6 Mageia Robot 2025-12-08 19:37:26 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0323.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.