CVE-2025-64720 is an out-of-bounds read vulnerability in libpng versions 1.6.0 through versions before 1.6.51. It affects png_image_read_composite when palette PNG images are processed with PNG_FLAG_OPTIMIZE_ALPHA enabled. In png_init_read_transformations, palette compositing incorrectly applies background compositing during premultiplication, violating the simplified PNG API invariant that a component must not exceed alpha multiplied by 257.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a working proof-of-concept (PoC) exploit for CVE-2025-64720, a high-severity out-of-bounds read vulnerability in libpng (< 1.6.51) affecting the palette premultiplication code path. The exploit is implemented as a set of Python scripts (notably generate-images.py) that generate specially crafted PNG files (exploit_v1.png, exploit_v2.png, etc.) designed to trigger the vulnerability when processed by a vulnerable libpng build. The repository includes a full copy of libpng-1.6.36 source code, build scripts (build.sh) for compiling libpng with various sanitizers, and example/test programs. The exploit targets applications using the simplified PNG API with alpha-capable output formats and demonstrates how a malicious PNG can cause a crash or information disclosure via OOB reads. No network endpoints are involved; the attack vector is file-based. The repository is well-structured for research, testing, and patch validation, and includes detailed documentation and legal disclaimers.
This repository is a comprehensive proof-of-concept (PoC) for CVE-2025-64720, a high-severity out-of-bounds read vulnerability in libpng (<1.6.51) when processing palette PNG images with transparency and alpha optimization. The exploit is not part of a framework but is a standalone PoC. The repository includes: - A detailed README.md with technical analysis, exploitation prerequisites, and references to upstream patches and bug reports. - A Python script (`generate-images.py`) that generates multiple variants of malicious PNG files designed to trigger the vulnerability by manipulating palette and tRNS chunks. - Build scripts and a full copy of the vulnerable libpng-1.6.36 source, including test and example programs. - The exploit works by supplying a crafted PNG file to a target application using the vulnerable libpng version and the simplified PNG API. When the file is processed, it causes an out-of-bounds read in the `png_sRGB_base` or `png_sRGB_delta` arrays, potentially leading to a heap-use-after-free, application crash, or information disclosure. No network endpoints or remote services are involved; the attack vector is a malicious file. The PoC is operational and can be used to verify the vulnerability or test defenses. The repository is well-structured, with clear separation between the PoC generator, build/test scripts, and the included libpng source.
This repository is a comprehensive proof-of-concept (PoC) for CVE-2025-64720, a high-severity out-of-bounds read vulnerability in libpng (<1.6.51) affecting palette image processing with transparency and alpha optimization. The repository contains: - A detailed README.md with technical analysis, exploitation prerequisites, and version detection methods. - A Python script (generate-images.py) that generates multiple variants of malicious PNG files designed to trigger the vulnerability by manipulating palette and alpha values. - A build.sh script to compile and test libpng with various sanitizers (ASan, UBSan, Valgrind) for vulnerability validation. - The full libpng-1.6.36 source code, including test and example programs, for building and testing the exploit in a controlled environment. The exploit works by generating PNG files that, when processed by a vulnerable libpng version in an application using the simplified API and requesting an alpha-capable output, cause an out-of-bounds read in the `png_sRGB_base` or `png_sRGB_delta` arrays. This can result in application crashes or information disclosure. The attack vector is file-based, requiring the victim to open a crafted PNG image. No network or remote endpoints are involved. The repository is well-structured for research, testing, and validation of the vulnerability, and does not contain fake or destructive code.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
39 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability addressed by the AlmaLinux 9.6 TuxCare security update. The supplied CVSS v2 vector indicates network-reachable exploitation with low complexity and no authentication, affecting confidentiality.
A network-accessible, low-complexity vulnerability requiring no authentication, with partial confidentiality impact and complete availability impact according to the supplied CVSS v2 vector.
A vulnerability included in the Alma Linux 9.6 TuxCare local security-check advisory. The content provides a CVSS v2 score source but no technical vulnerability description.
A vulnerability addressed by the referenced Rocky Linux/TuxCare security advisory; the supplied notice provides no technical flaw description or affected package name.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.