Version in base suite: 1.6.48-1+deb13u5 Base version: libpng1.6_1.6.48-1+deb13u5 Target version: libpng1.6_1.6.48-1+deb13u6 Base file: /srv/ftp-master.debian.org/ftp/pool/main/libp/libpng1.6/libpng1.6_1.6.48-1+deb13u5.dsc Target file: /srv/ftp-master.debian.org/policy/pool/main/libp/libpng1.6/libpng1.6_1.6.48-1+deb13u6.dsc changelog | 6 +++ patches/CVE-2026-46675.patch | 83 +++++++++++++++++++++++++++++++++++++++++++ patches/series | 1 3 files changed, 90 insertions(+) dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp7823ff2k/libpng1.6_1.6.48-1+deb13u5.dsc: no acceptable signature found dpkg-source: warning: cannot verify inline signature for /srv/release.debian.org/tmp/tmp7823ff2k/libpng1.6_1.6.48-1+deb13u6.dsc: no acceptable signature found diff -Nru libpng1.6-1.6.48/debian/changelog libpng1.6-1.6.48/debian/changelog --- libpng1.6-1.6.48/debian/changelog 2026-05-08 12:19:08.000000000 +0000 +++ libpng1.6-1.6.48/debian/changelog 2026-09-29 18:31:03.000000000 +0000 @@ -1,3 +1,9 @@ +libpng1.6 (1.6.48-1+deb13u6) trixie-security; urgency=medium + + * CVE-2026-46675 + + -- Moritz Mühlenhoff Tue, 29 Sep 2026 20:31:03 +0200 + libpng1.6 (1.6.48-1+deb13u5) trixie-security; urgency=high * Security upload targeting trixie. diff -Nru libpng1.6-1.6.48/debian/patches/CVE-2026-46675.patch libpng1.6-1.6.48/debian/patches/CVE-2026-46675.patch --- libpng1.6-1.6.48/debian/patches/CVE-2026-46675.patch 1970-01-01 00:00:00.000000000 +0000 +++ libpng1.6-1.6.48/debian/patches/CVE-2026-46675.patch 2026-09-29 12:35:46.000000000 +0000 @@ -0,0 +1,83 @@ +From aa77ef38c17ab2fc1b41bec09fb973c6a386641d Mon Sep 17 00:00:00 2001 +From: Cosmin Truta +Date: Wed, 23 Sep 2026 18:30:11 +0300 +Subject: [PATCH] fix: Clear stale zstream pointers when releasing the inflate + stream + +--- libpng1.6-1.6.48.orig/pngrutil.c ++++ libpng1.6-1.6.48/pngrutil.c +@@ -405,6 +405,18 @@ png_read_buffer(png_structrp png_ptr, pn + } + #endif /* READ_iCCP|iTXt|pCAL|sCAL|sPLT|tEXt|zTXt|eXIf|SEQUENTIAL_READ */ + ++/* Detach the zstream from the input and output buffers left by ++ * the current or a previous owner, and possibly deallocated since. ++ */ ++static void ++png_inflate_detach_buffers(png_structrp png_ptr) ++{ ++ png_ptr->zstream.next_in = NULL; ++ png_ptr->zstream.avail_in = 0; ++ png_ptr->zstream.next_out = NULL; ++ png_ptr->zstream.avail_out = 0; ++} ++ + /* png_inflate_claim: claim the zstream for some nefarious purpose that involves + * decompression. Returns Z_OK on success, else a zlib error code. It checks + * the owner but, in final release builds, just issues a warning if some other +@@ -465,13 +477,7 @@ png_inflate_claim(png_structrp png_ptr, + + #endif /* ZLIB_VERNUM >= 0x1240 */ + +- /* Set this for safety, just in case the previous owner left pointers to +- * memory allocations. +- */ +- png_ptr->zstream.next_in = NULL; +- png_ptr->zstream.avail_in = 0; +- png_ptr->zstream.next_out = NULL; +- png_ptr->zstream.avail_out = 0; ++ png_inflate_detach_buffers(png_ptr); + + if ((png_ptr->flags & PNG_FLAG_ZSTREAM_INITIALIZED) != 0) + { +@@ -808,7 +814,8 @@ png_decompress_chunk(png_structrp png_pt + else if (ret == Z_OK) + ret = PNG_UNEXPECTED_ZLIB_RETURN; + +- /* Release the claimed stream */ ++ /* Release the claimed stream. */ ++ png_inflate_detach_buffers(png_ptr); + png_ptr->zowner = 0; + } + +@@ -1491,6 +1498,7 @@ png_handle_iCCP(png_structrp png_ptr, pn + + if (errmsg == NULL) + { ++ png_inflate_detach_buffers(png_ptr); + png_ptr->zowner = 0; + return handled_ok; + } +@@ -1517,7 +1525,8 @@ png_handle_iCCP(png_structrp png_ptr, pn + else /* profile truncated */ + errmsg = png_ptr->zstream.msg; + +- /* Release the stream */ ++ /* Release the claimed stream. */ ++ png_inflate_detach_buffers(png_ptr); + png_ptr->zowner = 0; + } + +@@ -4344,11 +4353,7 @@ png_read_finish_IDAT(png_structrp png_pt + */ + if (png_ptr->zowner == png_IDAT) + { +- /* Always do this; the pointers otherwise point into the read buffer. */ +- png_ptr->zstream.next_in = NULL; +- png_ptr->zstream.avail_in = 0; +- +- /* Now we no longer own the zstream. */ ++ png_inflate_detach_buffers(png_ptr); + png_ptr->zowner = 0; + + /* The slightly weird semantics of the sequential IDAT reading is that we diff -Nru libpng1.6-1.6.48/debian/patches/series libpng1.6-1.6.48/debian/patches/series --- libpng1.6-1.6.48/debian/patches/series 2026-05-08 12:19:08.000000000 +0000 +++ libpng1.6-1.6.48/debian/patches/series 2026-09-29 12:35:33.000000000 +0000 @@ -19,3 +19,4 @@ CVE-2026-34757-part2.patch CVE-2026-33416-regression-fix.patch CVE-2026-33416-regression-fix-test.patch +CVE-2026-46675.patch