SUSE 5570 Published by

A security update for libpng16 has been released to address a heap buffer overflow vulnerability. The vulnerability, identified as CVE-2026-25646, was discovered in png_set_dither/png_set_quantize and can be fixed with the latest patch. Affected products include various SUSE Linux distributions such as openSUSE Leap 15.6 and SUSE Linux Enterprise Server 15 SP7. To install the update, users can run a command like "zypper in -t patch SUSE-2026-597=1" on their system.

SUSE-SU-2026:0597-1: important: Security update for libpng16




SUSE-SU-2026:0597-1: important: Security update for libpng16


# Security update for libpng16

Announcement ID: SUSE-SU-2026:0597-1
Release Date: 2026-02-23T15:58:22Z
Rating: important
References:

* bsc#1258020

Cross-References:

* CVE-2026-25646

CVSS scores:

* CVE-2026-25646 ( SUSE ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
* CVE-2026-25646 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
* CVE-2026-25646 ( NVD ): 8.3
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
* CVE-2026-25646 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products:

* Basesystem Module 15-SP7
* openSUSE Leap 15.6
* SUSE Linux Enterprise Desktop 15 SP7
* SUSE Linux Enterprise Real Time 15 SP7
* SUSE Linux Enterprise Server 15 SP6
* SUSE Linux Enterprise Server 15 SP6 LTSS
* SUSE Linux Enterprise Server 15 SP7
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
* SUSE Linux Enterprise Server for SAP Applications 15 SP7

An update that solves one vulnerability can now be installed.

## Description:

This update for libpng16 fixes the following issues:

* CVE-2026-25646: heap buffer overflow vulnerability in
png_set_dither/png_set_quantize (bsc#1258020).

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

* openSUSE Leap 15.6
zypper in -t patch SUSE-2026-597=1 openSUSE-SLE-15.6-2026-597=1

* Basesystem Module 15-SP7
zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-597=1

* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-597=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-597=1

## Package List:

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586)
* libpng16-16-1.6.40-150600.3.12.1
* libpng16-16-debuginfo-1.6.40-150600.3.12.1
* libpng16-devel-1.6.40-150600.3.12.1
* libpng16-tools-1.6.40-150600.3.12.1
* libpng16-compat-devel-1.6.40-150600.3.12.1
* libpng16-debugsource-1.6.40-150600.3.12.1
* libpng16-tools-debuginfo-1.6.40-150600.3.12.1
* openSUSE Leap 15.6 (x86_64)
* libpng16-16-32bit-debuginfo-1.6.40-150600.3.12.1
* libpng16-16-32bit-1.6.40-150600.3.12.1
* libpng16-devel-32bit-1.6.40-150600.3.12.1
* libpng16-compat-devel-32bit-1.6.40-150600.3.12.1
* openSUSE Leap 15.6 (aarch64_ilp32)
* libpng16-compat-devel-64bit-1.6.40-150600.3.12.1
* libpng16-16-64bit-debuginfo-1.6.40-150600.3.12.1
* libpng16-devel-64bit-1.6.40-150600.3.12.1
* libpng16-16-64bit-1.6.40-150600.3.12.1
* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)
* libpng16-16-1.6.40-150600.3.12.1
* libpng16-16-debuginfo-1.6.40-150600.3.12.1
* libpng16-devel-1.6.40-150600.3.12.1
* libpng16-compat-devel-1.6.40-150600.3.12.1
* libpng16-debugsource-1.6.40-150600.3.12.1
* Basesystem Module 15-SP7 (x86_64)
* libpng16-16-32bit-debuginfo-1.6.40-150600.3.12.1
* libpng16-16-32bit-1.6.40-150600.3.12.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* libpng16-16-1.6.40-150600.3.12.1
* libpng16-16-debuginfo-1.6.40-150600.3.12.1
* libpng16-devel-1.6.40-150600.3.12.1
* libpng16-compat-devel-1.6.40-150600.3.12.1
* libpng16-debugsource-1.6.40-150600.3.12.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64)
* libpng16-16-32bit-debuginfo-1.6.40-150600.3.12.1
* libpng16-16-32bit-1.6.40-150600.3.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* libpng16-16-1.6.40-150600.3.12.1
* libpng16-16-debuginfo-1.6.40-150600.3.12.1
* libpng16-devel-1.6.40-150600.3.12.1
* libpng16-compat-devel-1.6.40-150600.3.12.1
* libpng16-debugsource-1.6.40-150600.3.12.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64)
* libpng16-16-32bit-debuginfo-1.6.40-150600.3.12.1
* libpng16-16-32bit-1.6.40-150600.3.12.1

## References:

* https://www.suse.com/security/cve/CVE-2026-25646.html
* https://bugzilla.suse.com/show_bug.cgi?id=1258020