Out-of-Bounds Read Vulnerability in LIBPNG Affects Image Manipulation Capabilities
CVE-2025-64720
What is CVE-2025-64720?
An out-of-bounds read vulnerability exists in the LIBPNG library that can be exploited when processing palette images with the PNG_FLAG_OPTIMIZE_ALPHA flag enabled. The vulnerability arises in the png_image_read_composite function, where inadequate background compositing during premultiplication violates strict invariants needed for proper image rendering, potentially leading to information disclosure and unpredictable behavior. This issue has been addressed in version 1.6.51 of the library, emphasizing the importance of using updated software versions for secure image processing.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
libpng >= 1.6.0, < 1.6.51
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
