CVE-2025-65018
LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) raster image files. From version 1.6.0 to before 1.6.51, there is a heap buffer overflow vulnerability in the libpng simplified API function png_image_finish_read when processing 16-bit interlaced PNGs with 8-bit output format. Attacker-crafted interlaced PNG files cause heap writes beyond allocated buffer bounds. This issue has been patched in version 1.6.51.
- Affected products
- Alt Linux, Almalinux, Centos, Debian, Linuxmint, Playstation 4, Playstation 5, Red Hat
- Libpng
- < 1.6.51
- Fix
- Available
- CVSS 3.1
- 7.1 HIGH
- EPSS
- 0.3% (17th percentile)
- Weakness
- CWE-787, CWE-122
- NVD status
- Analyzed
- Published
- 2025-11-24
CVE-2025-65018 at NVD
5 known exploits for CVE-2025-65018
Proof-of-concept code and exploit modules indexed by Sploitus