alpine · CVE-2025-28162

Quick triage

Priority: not assigned Published: Updated:

View at Official alpine advisory, NVD, CVE.org · CVE detail

Freshness: no update timestamp found; verify against the upstream OS advisory manually.

Tracker summary

CVE-2025-28162: 1 source package rows (libpng); 6 state rows across 4 repos (3.19-main, 3.20-main, 3.21-main, edge-main); fixed 0, open 6.

Description:

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

cvelogic Threat Intelligence