CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-34757

mediumcovered by 2 sourcesfirst seen 2026-08-17
Patrick Keshishian discovered that libpng incorrectly handled certain text chunks. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2016-10087) It was discovered that libpng incorrectly handled certain malformed images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 18.04 LTS. (CVE-2018-14048) It was discovered that libpng incorrectly handled memory when freeing certain images. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2019-7317) It was discovered that libpng incorrectly handled memory when processing certain images. An attacker could possibly use this issue to cause a denial of service, or execute arbitrary code. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-33416) It was discovered that libpng incorrectly handled certain images. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. This issue only affected Ubuntu 20.04 LTS. (CVE-2026-33636) It was discovered that libpng incorrectly handled memory when processing certain images. An attacker could possibly use this issue to cause a denial of service or obtain sensitive information. This issue only affected Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu 20.04 LTS. (CVE-2026-34757) Seung Min Shin discovered that libpng incorrectly handled certain animated images. An attacker could possibly use this issue to cause libpng to misinterpret image data. This issue only affected Ubuntu 20.04 LTS and Ubuntu 22.04 LTS. (CVE-2026-40930)

CSIRTS triage

What
An information disclosure vulnerability allows local attackers to access sensitive data from libpng.
Who is affected
Systems using libpng library are affected; requires local access.
Urgency
Medium priority; information disclosure affects availability of confidential data.
Action
Update libpng to the latest patched version.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-34757

Get an email if CVE-2026-34757 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-34757

CVE.org record

Embed the live status

CVE-2026-34757 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-34757 status](https://www.csirts.com/badge/CVE-2026-34757)](https://www.csirts.com/cve/CVE-2026-34757)