CVE-2026-33416 is a use-after-free vulnerability in libpng affecting versions 1.2.1 through 1.6.55, with transparency-buffer aliasing dating back to at least version 1.0. The png_set_tRNS and png_set_PLTE functions share heap allocations between png_struct and png_info despite their independently managed lifetimes. The shared transparency and palette buffers are 256 and 768 bytes, respectively. Freeing the buffers through png_free_data, or replacing them through repeated setter calls, can leave dangling pointers in png_struct. Subsequent row-transform functions read and, in some code paths, write through these pointers, potentially enabling memory corruption and arbitrary code execution. Libpng 1.6.56 fixes the vulnerability.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
54 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity heap use-after-free vulnerability in libpng. Shared transparency and palette buffers can be freed through png_info while png_struct retains dangling pointers, allowing subsequent row transformations to read or write freed memory. Calling png_set_tRNS or png_set_PLTE again can also trigger the issue. The reference identifies versions 1.2.1 through 1.6.55 as affected and notes that transparency-buffer aliasing dates back to at least version 1.0. The CVSS v3 base score is 7.5. libpng 1.6.56 fixes the issue; the recommended package update is libpng1.6 version 1.6.56-1 or later.
A specific vulnerability referenced by the Alma Linux 9.2 TuxCare security-check plugin; no technical flaw details are provided.
A libpng use-after-free vulnerability that can permit arbitrary code execution.
An Important-severity vulnerability affecting AlmaLinux 9.2 systems covered by the referenced TuxCare/Alma Linux local security check. It can be attacked remotely without privileges but requires high attack complexity and user interaction; successful exploitation has high confidentiality, integrity, and availability impact.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.