CVE-2025-28162

MEDIUM

libpng 1.6.43-1.6.46 - Denial of Service via Buffer Overflow in pngimage

Title source: llm
STIX 2.1

Description

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-120
Status published
Products (1)
libpng/libpng 1.6.43 - 1.6.46
Published Jan 27, 2026
Tracked Since Feb 18, 2026