png_image_free in png.c in libpng 1.6.x before 1.6.37 has a use-after-free because png_image_free_function is called under png_safe_execute.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| libpng | libpng | 1.6.0 - 1.6.37 | - |
| debian | debian_linux | - | - |
| debian | debian_linux | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
56
Affected Products
84
References
libpng / libpng
| - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| canonical | ubuntu_linux | - | - |
| oracle | hyperion_infrastructure_technology | - | - |
| oracle | java_se | - | - |
| oracle | java_se | - | - |
| oracle | jdk | - | - |
| oracle | jdk | - | - |
| oracle | mysql | 8.0.23 | - |
| hp | xp7_command_view | 8.7.0-00 | - |
| hpe | xp7_command_view_advanced_edition_suite | 8.7.0-00 | - |
| mozilla | firefox | - | - |
| mozilla | thunderbird | - | - |
| opensuse | leap | - | - |
| opensuse | leap | - | - |
| opensuse | leap | - | - |
| opensuse | package_hub | - | - |
| netapp | active_iq_unified_manager | 9.6 | - |
| netapp | active_iq_unified_manager | 9.6 | - |
| netapp | active_iq_unified_manager | - | - |
| netapp | active_iq_unified_manager | - | - |
| netapp | cloud_backup | - | - |
| netapp | e-series_santricity_management | - | - |
| netapp | e-series_santricity_storage_manager | 11.53 | - |
| netapp | e-series_santricity_unified_manager | 3.2 | - |
| netapp | e-series_santricity_web_services | 4.0 | - |
| netapp | oncommand_insight | 7.3.9 | - |
| netapp | oncommand_workflow_automation | 5.1 | - |
| netapp | plug-in_for_symantec_netbackup | - | - |
| netapp | snapmanager | 3.4.2 | - |
| netapp | snapmanager | 3.4.2 | - |
| netapp | snapmanager | - | - |
| netapp | snapmanager | - | - |
| netapp | steelstore | - | - |
| redhat | satellite | - | - |
| redhat | enterprise_linux | - | - |
| redhat | enterprise_linux | - | - |
| redhat | enterprise_linux | - | - |
| redhat | enterprise_linux_desktop | - | - |
| redhat | enterprise_linux_desktop | - | - |
| redhat | enterprise_linux_for_ibm_z_systems | - | - |
| redhat | enterprise_linux_for_ibm_z_systems | - | - |
| redhat | enterprise_linux_for_ibm_z_systems | - | - |
| redhat | enterprise_linux_for_power_big_endian | - | - |
| redhat | enterprise_linux_for_power_big_endian | - | - |
| redhat | enterprise_linux_for_power_little_endian | - | - |
| redhat | enterprise_linux_for_power_little_endian | - | - |
| redhat | enterprise_linux_for_scientific_computing | - | - |
| redhat | enterprise_linux_for_scientific_computing | - | - |
| redhat | enterprise_linux_workstation | - | - |
| redhat | enterprise_linux_workstation | - | - |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability
Impact