From: Adolf Belka <adolf.belka@ipfire.org>
To: development@lists.ipfire.org
Cc: Adolf Belka <adolf.belka@ipfire.org>
Subject: [PATCH] libpng: Update to version 1.6.59
Date: Fri, 2 Oct 2026 13:23:25 +0200 [thread overview]
Message-ID: <20261002112330.3568361-8-adolf.belka@ipfire.org> (raw)
In-Reply-To: <20261002112330.3568361-1-adolf.belka@ipfire.org>
- Update from version 1.6.58 to 1.6.59
- Update of rootfile
- 1 CVE fix
- Changelog
1.6.59
Fixed CVE-2026-46675 (medium severity):
Use-after-free of zlib input in `png_read_end` after incomplete zTXt, iTXt
or iCCP decompression.
(Reported independently by Ze Sheng and
<JasonHonKL@users.noreply.github.com>.)
Fixed a regression introduced in version 1.6.47 that caused libpng to reject
hIST chunks in their correct position, after PLTE.
(Contributed by Yuki Sekiguchi.)
Prevented a double free of `png_struct` members after an allocation failure.
(Contributed by Anthony Hurtado.)
Applied fixes and updates to the CMake build.
Adopted the REUSE Specification for licensing the CI files.
Signed-off-by: Adolf Belka <adolf.belka@ipfire.org>
---
config/rootfiles/common/libpng | 2 +-
lfs/libpng | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
diff --git a/config/rootfiles/common/libpng b/config/rootfiles/common/libpng
index ef7d888f3..5c7cf4867 100644
--- a/config/rootfiles/common/libpng
+++ b/config/rootfiles/common/libpng
@@ -16,7 +16,7 @@ usr/lib/libpng.so
#usr/lib/libpng16.la
usr/lib/libpng16.so
usr/lib/libpng16.so.16
-usr/lib/libpng16.so.16.58.0
+usr/lib/libpng16.so.16.59.0
#usr/lib/pkgconfig/libpng.pc
#usr/lib/pkgconfig/libpng16.pc
#usr/share/man/man3/libpng.3
diff --git a/lfs/libpng b/lfs/libpng
index 6aa7fbee9..2375432b0 100644
--- a/lfs/libpng
+++ b/lfs/libpng
@@ -24,7 +24,7 @@
include Config
-VER = 1.6.58
+VER = 1.6.59
THISAPP = libpng-$(VER)
DL_FILE = $(THISAPP).tar.xz
@@ -40,7 +40,7 @@ objects = $(DL_FILE)
$(DL_FILE) = $(DL_FROM)/$(DL_FILE)
-$(DL_FILE)_BLAKE2 = 51042e8f2b56d469b516db9cbde6d4b6813a62d1b7117898ba32a9a5ac5cd73832c627d7377745e5d5154aade6ec6928fc6b9cd9b96885f64b7ca7df19ca40ec
+$(DL_FILE)_BLAKE2 = f2656b0d9a3865faf957e8600a7617516d9139d15c6d7581c06b4829b4c9338ec5f747e4ccfcc49b6b9f5a96f0476121eda99457469c8e1cfecd8ecc3b1697ed
install : $(TARGET)
--
2.55.0
next prev parent reply other threads:[~2026-10-02 11:23 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 11:23 [PATCH] core205: Ship gdb Adolf Belka
2026-10-02 11:23 ` [PATCH] core205: Ship libpng Adolf Belka
2026-10-02 11:23 ` [PATCH] core205: Ship pam Adolf Belka
2026-10-02 11:23 ` [PATCH] freeradius: Update to version 3.2.10 Adolf Belka
2026-10-02 11:23 ` [PATCH] gdb: Update to version 18.1 Adolf Belka
2026-10-02 11:23 ` [PATCH] git: Update to version 2.56.0 Adolf Belka
2026-10-02 11:23 ` [PATCH] iperf3: Update to version 3.22 Adolf Belka
2026-10-02 11:23 ` Adolf Belka [this message]
2026-10-02 11:23 ` [PATCH] ntfs-3g: Update to version 2026.9.28 Adolf Belka
2026-10-02 11:23 ` [PATCH] pam: Update to version 1.7.3 Adolf Belka
2026-10-02 11:23 ` [PATCH] pcre2: Update to version 10.49 Adolf Belka
2026-10-02 11:23 ` [PATCH] shairport-sync: Update to version 5.5.2 Adolf Belka
2026-10-02 11:23 ` [PATCH] swtpm: Update to version 0.10.2 Adolf Belka
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002112330.3568361-8-adolf.belka@ipfire.org \
--to=adolf.belka@ipfire.org \
--cc=development@lists.ipfire.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox