CVE-2025-66293

Public on 2025-12-03
Modified on 2025-12-11
Description
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. Prior to 1.6.52, an out-of-bounds read vulnerability in libpng's simplified API allows reading up to 1012 bytes beyond the png_sRGB_base[512] array when processing valid palette PNG images with partial transparency and gamma correction. The PNG files that trigger this vulnerability are valid per the PNG specification; the bug is in libpng's internal state management. Upgrade to libpng 1.6.52 or later.
Severity
Important severity
Important
See what this means
CVSS v3 Base Score
7.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Firefox Extra firefox 2026-01-05 ALAS2FIREFOX-2025-049 Fixed
Amazon Linux 2023 firefox 2026-01-07 ALAS2023-2025-1337 Fixed
Amazon Linux 2 - Core libpng Not Affected
Amazon Linux 2023 libpng 2026-01-07 ALAS2023-2025-1332 Fixed
Amazon Linux 2 - Core thunderbird 2026-01-05 ALAS2-2025-3108 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H