Reference: https://www.openwall.com/lists/oss-security/2026/03/26/1
Whiteboard: (none) => MGA9TOOSource RPM: (none) => libpng-1.6.53-3.mga10.src.rpm, libpng-1.6.38-1.4.mga9.src.rpmFlags: (none) => affects_mga9+Status comment: (none) => Fixed upstream in 1.6.56CVE: (none) => CVE-2026-33416, CVE-2026-33636
For Cauldron, libpng-1.6.53-4.mga10 fixes those issues.
Whiteboard: MGA9TOO => (none)Source RPM: libpng-1.6.53-3.mga10.src.rpm, libpng-1.6.38-1.4.mga9.src.rpm => libpng-1.6.38-1.4.mga9.src.rpmVersion: Cauldron => 9Flags: affects_mga9+ => (none)
Status comment: Fixed upstream in 1.6.56 => Fixed upstream in 1.6.56 and patches available from upstream
Suggested advisory: ======================== The updated packages fix a security vulnerability: Use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE. (CVE-2026-33416) Out-of-bounds read/write in the palette expansion on ARM Neon. (CVE-2026-33636) References: https://www.openwall.com/lists/oss-security/2026/03/26/1 ======================== Updated packages in core/updates_testing: ======================== lib(64)png16_16-1.6.38-1.5.mga9 lib(64)png-devel-1.6.38-1.5.mga9 from SRPM: libpng-1.6.38-1.5.mga9.src.rpm
Assignee: bugsquad => qa-bugsStatus: NEW => ASSIGNEDStatus comment: Fixed upstream in 1.6.56 and patches available from upstream => (none)
MGA9-64 server Plasma Wayland on Compaq H000SB. No installation issues. Ref bug 35115 Opened png file with inkscape and gimp, did some editing and exported result to png. Resulting files open correctly in gwenview. Looks OK.
Whiteboard: (none) => MGA9-64-OKFlags: (none) => test_passed_mga9_64+CC: (none) => herman.viaene
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => advisory
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2026-0070.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED