Release date:
2026-08-05 13:42:11 UTC
Description:
* SECURITY UPDATE: out-of-bounds read/write in ARM NEON palette expansion
- debian/patches/CVE-2026-33636.patch: restrict the NEON loop in
png_do_expand_palette_rgba8_neon and png_do_expand_palette_rgb8_neon
(arm/palette_neon_intrinsics.c) to full chunks only, so rows whose
width is not a multiple of the chunk size no longer read or write
past the row buffer
- CVE-2026-33636
Updated packages:
-
libpng-dev_1.6.37-2+tuxcare.els4_amd64.deb
sha:3c210382e66eb476d2e06fb5472212ecfd93b850
-
libpng-tools_1.6.37-2+tuxcare.els4_amd64.deb
sha:881e26204e3bf1aa3284cd81a3d0b411484926a7
-
libpng16-16_1.6.37-2+tuxcare.els4_amd64.deb
sha:8e2d06a4ee0daabef8791bf4439ed1e7e999c4de
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.