CVE-2026-64612: Red Hat Enterprise Linux 10

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 1:2.0.0-13.el10_2 (fixed in 1:2.0.0-13.el10_2)
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8: before 0:1.20.0-36.el8_10.1 (fixed in 0:1.20.0-36.el8_10.1)
  • Red Hat Red Hat Enterprise Linux 9: before 0:1.28.7-27.el9_8 (fixed in 0:1.28.7-27.el9_8)

Published 2026-07-20. Last modified 2026-08-24.