[CLSA-2026:1785937319] Fix CVE(s): CVE-2026-33416, CVE-2026-33636
Type:
security
Severity:
Important
Release date:
2026-08-05 13:42:11 UTC
Description:
* SECURITY UPDATE: out-of-bounds read/write in ARM NEON palette expansion - debian/patches/CVE-2026-33636.patch: restrict the NEON loop in png_do_expand_palette_rgba8_neon and png_do_expand_palette_rgb8_neon (arm/palette_neon_intrinsics.c) to full chunks only, so rows whose width is not a multiple of the chunk size no longer read or write past the row buffer - CVE-2026-33636
Updated packages:
  • libpng-dev_1.6.37-2+tuxcare.els4_amd64.deb
    sha:3c210382e66eb476d2e06fb5472212ecfd93b850
  • libpng-tools_1.6.37-2+tuxcare.els4_amd64.deb
    sha:881e26204e3bf1aa3284cd81a3d0b411484926a7
  • libpng16-16_1.6.37-2+tuxcare.els4_amd64.deb
    sha:8e2d06a4ee0daabef8791bf4439ed1e7e999c4de
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.