CVE-2026-34757Disclosure(debian / debian_linux)

LOWCVSS 4.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch debian debian_linux systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.57, passing a pointer obtained from png_get_PLTE, png_get_tRNS, or png_get_hIST back into the corresponding setter on the same png_struct/png_info pair causes the setter to read from freed memory and copy its contents into the replacement buffer. The setter frees the internal buffer before copying from the caller-supplied pointer, which now dangles. The freed region may contain stale data (producing silently corrupted chunk metadata) or data from subsequent heap allocations (leaking unrelated heap contents into the chunk struct). This vulnerability is fixed in 1.6.57.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • libpng

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
debian_linuxlibpng

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-09: 2Mentions · 2026-04-10: 1Mentions · 2026-05-02: 1Patch / Workaround · 2026-04-10: 1Technical Details · 2026-04-10: 1Technical Details · 2026-05-02: 104-0904-1005-02
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-092
Disclosure1General1
2026-04-101
Disclosure1
2026-05-021
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-34757: libpng: Use-after-free in png_set_PLTE, png_set_tRNS, png_set_hIST https://www.openwall.com/lists/oss-security/2026/04/09/2 leading to corrupted chunk data and potential heap information disclosure. The defect cannot be triggered by a crafted PNG file alone. Medium severity. Fixed in 1.6.57.

    Post summary

    A medium‑severity use‑after‑free vulnerability (CVE‑2026‑34757) in libpng has been announced, affecting png_set_PLTE, png_set_tRNS, and png_set_hIST functions; it has been patched in version 1.6.57 and is not reported to be actively exploited.

    01052472
    4.6K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2026-34757 impacts libpng in 6 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/487 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new medium‑severity CVE (CVE‑2026‑34757) affecting libpng in AWS Lambda base images has been identified, with details posted on GitHub and Lambdawatchdog.

    0000035
    32 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-34757 LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From 1.0.9 to before 1.6.5… https://www.cve.org/CVERecord?id=CVE-2026-34757

    Post summary

    The text merely references CVE‑2026‑34757 and its version range, linking to the official CVE record without providing actionable or technical details.

    00000137
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-34757 libpng 1.6.57 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-34757

    Post summary

    The text simply cites CVE‑2026‑34757 for libpng 1.6.57 and provides a link to a vulnerability record without offering additional technical or exploitation information.

    0000045
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Applibpnglibpng---

Explore more