CVE-2026-33636Patch(libpng / libpng)

LOWCVSS 7.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch libpng libpng systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through 1.6.55, an out-of-bounds read and write exists in libpng's ARM/AArch64 Neon-optimized palette expansion path. When expanding 8-bit paletted rows to RGB or RGBA, the Neon loop processes a final partial chunk without verifying that enough input pixels remain. Because the implementation works backward from the end of the row, the final iteration dereferences pointers before the start of the row buffer (OOB read) and writes expanded pixel data to the same underflowed positions (OOB write). This is reachable via normal decoding of attacker-controlled PNG input if Neon is enabled. Version 1.6.56 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libpng

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-03-26); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
libpng

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-03-26: 2Mentions · 2026-03-27: 1Mentions · 2026-03-28: 1Mentions · 2026-03-30: 2Mentions · 2026-03-31: 1Mentions · 2026-04-07: 1Mentions · 2026-07-29: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-03-30: 1Patch / Workaround · 2026-04-07: 1Patch / Workaround · 2026-07-29: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-30: 2Technical Details · 2026-03-31: 1Technical Details · 2026-04-07: 103-2603-2703-2803-3003-3104-0707-29
Signal classification3 categories
Patch
444.4%
Disclosure
333.3%
General
222.2%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-262
General1Patch1
2026-03-271
Disclosure1
2026-03-281
Patch1
2026-03-302
Disclosure2
2026-03-311
General1
2026-04-071
Patch1
2026-07-291
Patch1
Full discourse9 posts
  • Open Source Security mailing list@oss_security
    Patch

    2 CVEs in libpng https://www.openwall.com/lists/oss-security/2026/03/26/1 libpng 1.6.56 has been released, fixing two high-severity CVEs CVE-2026-33416: Use-after-free via pointer aliasing in png_set_tRNS and png_set_PLTE CVE-2026-33636: Out-of-bounds read/write in the palette expansion on ARM Neon

    Post summary

    The announcement notes that libpng 1.6.56 fixes two high‑severity vulnerabilities, detailing a use‑after‑free and an out‑of‑bounds read/write, and includes a reference to the release.

    030104985
    4.4K followersView on X
  • Md. Najeeb Hussain@mnh_18
    Patch

    Full CVE list confirmed for the specific critical bugs: CVE-2026-27280, CVE-2026-28590, CVE-2026-28618, CVE-2026-28639, and CVE-2026-33636. Five critical Android flaws, all named, all fixed. Genuinely transparent disclosure — Samsung's not hiding the specifics this time. 📋 #Samsung #CVE #SecurityPatch #GalaxyS26

    Post summary

    The post confirms five critical Android CVEs and notes that Samsung has fixed them, indicating availability of vendor patches.

    000150926
    810 followersView on X
  • hirotaka.fukkoshi@情報教育のひと@HFukkoshi
    General

    cvss3.1で基本スコア7.6 劇ヤバクラス https://nvd.nist.gov/vuln/detail/CVE-2026-33636

    Post summary

    The post only notes the CVSS score of CVE-2026-33636 and links to the NVD entry, providing minimal technical detail.

    00011395
    547 followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    Researchers reveal critical RCE and ARM-specific flaws in libpng (CVE-2026-33636 & 33416). Affecting decades of apps, these bugs require an immediate update. #libpng #CyberSecurity #RCE #InfoSec #ARM #Vulnerability #PatchNow #ImageProcessing #Exploit https://securityonline.info/libpng-vulnerability-rce-arm-neon-cve-2026-33636-cve-2026-33416/ https://t.co/DIPnyGnutN

    Post summary

    Researchers announced critical return‑to‑zero‑execution (RCE) flaws in libpng that affect many applications, emphasizing the need for immediate updates.

    00011448
    11.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33636 libpng 1.6.56 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33636 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The content references a CVE and affected software version but provides no technical detail, PoC, active exploitation claim, or patch information.

    00011128
    4.0K followersView on X
  • iototsecnews@iototsecnews
    Patch

    PNG ライブラリ libpng の脆弱性 CVE-2026-33416/33636 が FIX:クラッシュと情報漏洩の恐れ https://iototsecnews.jp/2026/03/31/png-vulnerabilities-allow-attackers-to-trigger-crashes-and-leak-sensitive-data/ 画像処理の基盤として広く使われている PNG ライブラリ libpng に発見された、2 件の深刻な脆弱性について解説する記事です。 これらの問題の原因は、メモリ管理の不備と、高速化のためのプログラム処理における境界チェックの不足にあります。 1 つ目の脆弱性 CVE-2026-33416 (CVSS 8.1) は、画像の透過情報やパレット情報を扱う際のメモリの二重管理に起因します。 2 つ目の脆弱性 CVE-2026-33636 (CVSS 7.1) は、ARM プロセッサ向けの高速化機能 (Neon) を使っている場合に発生します。 ご利用のチームは、ご注意ください。 #CVE202633416 #CVE202633636 #libpng #Vulnerability

    Post summary

    The article explains two significant libpng vulnerabilities, details their technical causes, and notes that fixes are available.

    01000176
    483 followersView on X
  • CrowdCyber 🌐@CrowdCyber_Com
    Disclosure

    The 30-Year Glitch: RCE and ARM Exploits Uncovered in libpng Reference Library https://securityonline.info/libpng-vulnerability-rce-arm-neon-cve-2026-33636-cve-2026-33416/

    Post summary

    The article announces the discovery of remote code execution vulnerabilities in libpng’s ARM library, naming the affected CVEs, but it does not provide a PoC, exploit code, or patch details.

    00001168
    242 followersView on X
  • Joel B.D.@darkshram
    Patch

    Disponible LibPNG 1.6.56 en ALDOS, corrigiendo vulnerabilidades CVE-2026-33416 y CVE-2026-33636 vía @darkshram https://www.alcancelibre.org/noticias/disponible-libpng-1-6-56-en-aldos-corrigiendo-vulnerabilidades-cve-2026-33416-y-cve-2026-33636

    Post summary

    The announcement notes that LibPNG 1.6.56, which fixes CVE‑2026‑33416 and CVE‑2026‑33636, has been released in the ALDOS distribution, indicating a patch update.

    00010125
    1.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33636 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. In versions 1.6.36 through… https://www.cve.org/CVERecord?id=CVE-2026-33636

    Post summary

    The post announces CVE-2026-33636 for LIBPNG versions 1.6.36 onward, linking to the CVE record but offering no technical details, PoC, or exploitation information.

    00000206
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibpnglibpng---

Explore more