Skip to content

[AUTOPATCHER-CORE] Upgrade libpng to 1.6.55 for CVE-2026-25646#15789

Merged
jslobodzian merged 2 commits intofasttrack/3.0from
cblmargh/libpng-upgrade-to-1.6.55-fasttrack/3.0
Feb 12, 2026
Merged

[AUTOPATCHER-CORE] Upgrade libpng to 1.6.55 for CVE-2026-25646#15789
jslobodzian merged 2 commits intofasttrack/3.0from
cblmargh/libpng-upgrade-to-1.6.55-fasttrack/3.0

Conversation

@CBL-Mariner-Bot
Copy link
Collaborator

[AUTOPATCHER-CORE] Upgrade libpng to 1.6.55 for CVE-2026-25646
Upgrade pipeline run -> https://dev.azure.com/mariner-org/mariner/_build/results?buildId=1047003&view=results

@Kanishk-Bansal
Copy link
Contributor

Build

@Kanishk-Bansal
Copy link
Contributor

pnggroup/libpng@01d03b8 fixes the CVE and the change is verified to be in https://github.com/pnggroup/libpng/releases/tag/v1.6.55

Copy link
Member

@MadhurAggarwal MadhurAggarwal left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Changes Look good to me and Buddy Build Passed

@MadhurAggarwal MadhurAggarwal added the CVEFixReadyForMaintainerReview When a CVE fix has been reviewed by release manager and is ready for stable maintainer review label Feb 11, 2026
@Kanishk-Bansal Kanishk-Bansal added CVE-fixed-by-upgrade CVE fixed by package upgrade security labels Feb 11, 2026
@jslobodzian jslobodzian merged commit 8f875c6 into fasttrack/3.0 Feb 12, 2026
19 of 23 checks passed
@jslobodzian jslobodzian deleted the cblmargh/libpng-upgrade-to-1.6.55-fasttrack/3.0 branch February 12, 2026 00:19
CBL-Mariner-Bot added a commit that referenced this pull request Feb 12, 2026
Co-authored-by: jslobodzian <joslobo@microsoft.com>
(cherry picked from commit 8f875c6)
@CBL-Mariner-Bot
Copy link
Collaborator Author

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Automatic PR AutoUpgrade Core CVE-fixed-by-upgrade CVE fixed by package upgrade CVEFixReadyForMaintainerReview When a CVE fix has been reviewed by release manager and is ready for stable maintainer review fasttrack/3.0 PRs Destined for Azure Linux 3.0 Packaging security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants