CVE-2025-28162

MEDIUM

Libpng < 1.6.46 - Buffer Overflow

Title source: rule
STIX 2.1

Description

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

Scores

CVSS v3 5.5
EPSS 0.0002
EPSS Percentile 4.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (1)
libpng/libpng 1.6.43 - 1.6.46
Published Jan 27, 2026
Tracked Since Feb 18, 2026