[El-errata] ELSA-2026-43702 Moderate: Oracle Linux 7 libpng12 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Mon Aug 10 22:42:55 UTC 2026


Oracle Linux Security Advisory ELSA-2026-43702

http://linux.oracle.com/errata/ELSA-2026-43702.html

The following updated rpms for Oracle Linux 7 have been uploaded to the Unbreakable Linux Network:

x86_64:
libpng12-1.2.50-10.0.3.el7.i686.rpm
libpng12-1.2.50-10.0.3.el7.x86_64.rpm
libpng12-devel-1.2.50-10.0.3.el7.i686.rpm
libpng12-devel-1.2.50-10.0.3.el7.x86_64.rpm


SRPMS:
http://oss.oracle.com/ol7/SRPMS-updates/libpng12-1.2.50-10.0.3.el7.src.rpm

Related CVEs:

CVE-2026-33416




Description of changes:

[1.2.50-10.0.3]
- Fix CVE-2026-33416: use-after-free via pointer aliasing in png_set_tRNS and
  png_set_PLTE [Orabug: 39771480]

[1.2.50-10.0.1]
- Fix CVE-2026-25646: heap buffer overflow in png_set_quantize [Orabug: 39183864]




More information about the El-errata mailing list