{"id":374887,"date":"2026-08-12T02:20:00","date_gmt":"2026-08-12T09:20:00","guid":{"rendered":"https:\/\/cms-articles.softonic.io\/en\/?p=374887"},"modified":"2026-08-12T02:20:05","modified_gmt":"2026-08-12T09:20:05","slug":"libpng-updates-to-fix-a-1995-flaw-17-decades-old-bugs-still-linger","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/en\/libpng-updates-to-fix-a-1995-flaw-17-decades-old-bugs-still-linger\/","title":{"rendered":"libpng updates to fix a 1995 flaw: 17 decades-old bugs still linger"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Libpng, the PNG image library sitting under a huge amount of software, got an update in February 2026 to fix CVE-2026-25646. This one goes all the way back to 1995. It was rated <strong>high severity<\/strong>, and it was also one of 17 vulnerabilities that stayed buried for more than a decade.<\/p>\n\n<p class=\"wp-block-paragraph\">The flaw is a <strong>heap buffer overflow<\/strong> in the rarely used `png_set_quantize` function. A maliciously crafted PNG could crash an app and, in the worst case, expose information or open the door to remote code execution. Vulnerable libpng builds showed up in <a href=\"https:\/\/debian.en.softonic.com\/\" rel=\"noopener\">Debian<\/a>, Red Hat, <a href=\"https:\/\/ubuntu.en.softonic.com\/\" rel=\"noopener\">Ubuntu<\/a>, desktop applications, and some Java runtimes. It&#8217;s a good example of how code written in the early Unix and DOS years still ends up inside current systems, even when actually exploiting the bug may not be easy.<\/p>\n\n<p class=\"wp-block-paragraph\">PrintDemon follows the same script. It was a <a href=\"https:\/\/windows-10.en.softonic.com\/\" rel=\"noopener\">Windows<\/a> printer weakness introduced in 1996 and not fixed until <strong>May 2020<\/strong>. What started as a permissive design choice to make printer setup easier turned into a security problem years later.<\/p>\n\n<p class=\"wp-block-paragraph\">If you&#8217;re responsible for <a href=\"https:\/\/linux-mint.en.softonic.com\/\" rel=\"noopener\">Linux<\/a>, Windows, operational technology, or critical infrastructure, both the libpng fixes and the Windows patches are worth installing. Organizations still take <strong>more than 100 days<\/strong> on average to patch. Nearly 60% of compromises involve unpatched vulnerabilities. And older unsupported systems often don&#8217;t have strong access controls or modern encryption in place.<\/p>\n\n<p class=\"wp-block-paragraph\">Get the patched versions from your Linux distribution, the affected application or Java runtime update, and <a href=\"https:\/\/en.softonic.com\/articles\/windows-finally-fixes-80-hot-cybersecurity-issues\" rel=\"noopener\">Windows Update<\/a>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Libpng, the PNG image library sitting under a huge amount of software, got an update in February 2026 to fix CVE-2026-25646. This one goes all the way back to 1995. It was rated high severity, and it was also one of 17 vulnerabilities that stayed buried for more than a decade. The flaw is a &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/en\/libpng-updates-to-fix-a-1995-flaw-17-decades-old-bugs-still-linger\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;libpng updates to fix a 1995 flaw: 17 decades-old bugs still linger&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9332,"featured_media":374886,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":0},"categories":[1015],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-374887","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/374887","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/users\/9332"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/comments?post=374887"}],"version-history":[{"count":1,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/374887\/revisions"}],"predecessor-version":[{"id":374888,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/posts\/374887\/revisions\/374888"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media\/374886"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/media?parent=374887"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/categories?post=374887"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/tags?post=374887"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/usertag?post=374887"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/vertical?post=374887"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/en\/wp-json\/wp\/v2\/content-category?post=374887"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}