From bb34d495542e84911bfaa68a06b8c8b9ce67a39a Mon Sep 17 00:00:00 2001 From: Andrew Lukoshko Date: Wed, 7 Jan 2026 14:22:55 +0000 Subject: [PATCH] import CS mingw-libpng-1.6.34-1.el8 --- .gitignore | 2 +- .mingw-libpng.metadata | 2 +- SOURCES/libpng-1.6-CVE-2025-64720.patch | 69 ++++++++++ SOURCES/libpng-1.6-CVE-2025-65018_p1of2.patch | 25 ++++ SOURCES/libpng-1.6-CVE-2025-65018_p2of2.patch | 130 ++++++++++++++++++ SOURCES/libpng-1.6-CVE-2025-66293_p1of2.patch | 21 +++ SOURCES/libpng-1.6-CVE-2025-66293_p2of2.patch | 88 ++++++++++++ SOURCES/libpng-CVE-2018-13785.patch | 34 +++++ SOURCES/libpng-coverity.patch | 12 ++ SOURCES/libpng-fix-arm-neon.patch | 39 ++++++ SOURCES/libpng-multilib.patch | 23 ++++ SOURCES/pngusr.dfa | 4 + SPECS/mingw-libpng.spec | 39 +++++- 13 files changed, 483 insertions(+), 5 deletions(-) create mode 100644 SOURCES/libpng-1.6-CVE-2025-64720.patch create mode 100644 SOURCES/libpng-1.6-CVE-2025-65018_p1of2.patch create mode 100644 SOURCES/libpng-1.6-CVE-2025-65018_p2of2.patch create mode 100644 SOURCES/libpng-1.6-CVE-2025-66293_p1of2.patch create mode 100644 SOURCES/libpng-1.6-CVE-2025-66293_p2of2.patch create mode 100644 SOURCES/libpng-CVE-2018-13785.patch create mode 100644 SOURCES/libpng-coverity.patch create mode 100644 SOURCES/libpng-fix-arm-neon.patch create mode 100644 SOURCES/libpng-multilib.patch create mode 100644 SOURCES/pngusr.dfa diff --git a/.gitignore b/.gitignore index 699f95f..a0b94b9 100644 --- a/.gitignore +++ b/.gitignore @@ -1 +1 @@ -SOURCES/libpng-1.6.29.tar.xz +SOURCES/libpng-1.6.34.tar.xz diff --git a/.mingw-libpng.metadata b/.mingw-libpng.metadata index a1769c9..2ed0ef5 100644 --- a/.mingw-libpng.metadata +++ b/.mingw-libpng.metadata @@ -1 +1 @@ -7dbe6a5088b938545fc0857c507d4e0cf5d9023e SOURCES/libpng-1.6.29.tar.xz +45de4ec996ffcc3e18037e7c128abe95f4d0292a SOURCES/libpng-1.6.34.tar.xz diff --git a/SOURCES/libpng-1.6-CVE-2025-64720.patch b/SOURCES/libpng-1.6-CVE-2025-64720.patch new file mode 100644 index 0000000..0f29d7e --- /dev/null +++ b/SOURCES/libpng-1.6-CVE-2025-64720.patch @@ -0,0 +1,69 @@ +diff --git a/pngrtran.c b/pngrtran.c +index 548780030a..2f52022551 100644 +--- a/pngrtran.c ++++ b/pngrtran.c +@@ -1781,19 +1781,51 @@ png_init_read_transformations(png_structrp png_ptr) + } + else /* if (png_ptr->trans_alpha[i] != 0xff) */ + { +- png_byte v, w; +- +- v = png_ptr->gamma_to_1[palette[i].red]; +- png_composite(w, v, png_ptr->trans_alpha[i], back_1.red); +- palette[i].red = png_ptr->gamma_from_1[w]; +- +- v = png_ptr->gamma_to_1[palette[i].green]; +- png_composite(w, v, png_ptr->trans_alpha[i], back_1.green); +- palette[i].green = png_ptr->gamma_from_1[w]; +- +- v = png_ptr->gamma_to_1[palette[i].blue]; +- png_composite(w, v, png_ptr->trans_alpha[i], back_1.blue); +- palette[i].blue = png_ptr->gamma_from_1[w]; ++ if ((png_ptr->flags & PNG_FLAG_OPTIMIZE_ALPHA) != 0) ++ { ++ /* Premultiply only: ++ * component = round((component * alpha) / 255) ++ */ ++ png_uint_32 component; ++ ++ component = png_ptr->gamma_to_1[palette[i].red]; ++ component = ++ (component * png_ptr->trans_alpha[i] + 128) / 255; ++ palette[i].red = png_ptr->gamma_from_1[component]; ++ ++ component = png_ptr->gamma_to_1[palette[i].green]; ++ component = ++ (component * png_ptr->trans_alpha[i] + 128) / 255; ++ palette[i].green = png_ptr->gamma_from_1[component]; ++ ++ component = png_ptr->gamma_to_1[palette[i].blue]; ++ component = ++ (component * png_ptr->trans_alpha[i] + 128) / 255; ++ palette[i].blue = png_ptr->gamma_from_1[component]; ++ } ++ else ++ { ++ /* Composite with background color: ++ * component = ++ * alpha * component + (1 - alpha) * background ++ */ ++ png_byte v, w; ++ ++ v = png_ptr->gamma_to_1[palette[i].red]; ++ png_composite(w, v, ++ png_ptr->trans_alpha[i], back_1.red); ++ palette[i].red = png_ptr->gamma_from_1[w]; ++ ++ v = png_ptr->gamma_to_1[palette[i].green]; ++ png_composite(w, v, ++ png_ptr->trans_alpha[i], back_1.green); ++ palette[i].green = png_ptr->gamma_from_1[w]; ++ ++ v = png_ptr->gamma_to_1[palette[i].blue]; ++ png_composite(w, v, ++ png_ptr->trans_alpha[i], back_1.blue); ++ palette[i].blue = png_ptr->gamma_from_1[w]; ++ } + } + } + else diff --git a/SOURCES/libpng-1.6-CVE-2025-65018_p1of2.patch b/SOURCES/libpng-1.6-CVE-2025-65018_p1of2.patch new file mode 100644 index 0000000..5543eb7 --- /dev/null +++ b/SOURCES/libpng-1.6-CVE-2025-65018_p1of2.patch @@ -0,0 +1,25 @@ +diff --git a/pngread.c b/pngread.c +index 212afb7d21..92571ec335 100644 +--- a/pngread.c ++++ b/pngread.c +@@ -4040,6 +4040,20 @@ png_image_finish_read(png_imagep image, png_const_colorp background, + int result; + png_image_read_control display; + ++ /* Reject bit depth mismatches to avoid buffer overflows. */ ++ png_uint_32 ihdr_bit_depth = ++ image->opaque->png_ptr->bit_depth; ++ int requested_linear = ++ (image->format & PNG_FORMAT_FLAG_LINEAR) != 0; ++ if (ihdr_bit_depth == 16 && !requested_linear) ++ return png_image_error(image, ++ "png_image_finish_read: " ++ "16-bit PNG must use 16-bit output format"); ++ if (ihdr_bit_depth < 16 && requested_linear) ++ return png_image_error(image, ++ "png_image_finish_read: " ++ "8-bit PNG must not use 16-bit output format"); ++ + memset(&display, 0, (sizeof display)); + display.image = image; + display.buffer = buffer; diff --git a/SOURCES/libpng-1.6-CVE-2025-65018_p2of2.patch b/SOURCES/libpng-1.6-CVE-2025-65018_p2of2.patch new file mode 100644 index 0000000..e048345 --- /dev/null +++ b/SOURCES/libpng-1.6-CVE-2025-65018_p2of2.patch @@ -0,0 +1,130 @@ +diff --git a/pngread.c b/pngread.c +index 92571ec335..79917daaaf 100644 +--- a/pngread.c ++++ b/pngread.c +@@ -3129,6 +3129,54 @@ png_image_read_colormapped(png_voidp argument) + } + } + ++/* Row reading for interlaced 16-to-8 bit depth conversion with local buffer. */ ++static int ++png_image_read_direct_scaled(png_voidp argument) ++{ ++ png_image_read_control *display = png_voidcast(png_image_read_control*, ++ argument); ++ png_imagep image = display->image; ++ png_structrp png_ptr = image->opaque->png_ptr; ++ png_bytep local_row = png_voidcast(png_bytep, display->local_row); ++ png_bytep first_row = png_voidcast(png_bytep, display->first_row); ++ ptrdiff_t row_bytes = display->row_bytes; ++ int passes; ++ ++ /* Handle interlacing. */ ++ switch (png_ptr->interlaced) ++ { ++ case PNG_INTERLACE_NONE: ++ passes = 1; ++ break; ++ ++ case PNG_INTERLACE_ADAM7: ++ passes = PNG_INTERLACE_ADAM7_PASSES; ++ break; ++ ++ default: ++ png_error(png_ptr, "unknown interlace type"); ++ } ++ ++ /* Read each pass using local_row as intermediate buffer. */ ++ while (--passes >= 0) ++ { ++ png_uint_32 y = image->height; ++ png_bytep output_row = first_row; ++ ++ for (; y > 0; --y) ++ { ++ /* Read into local_row (gets transformed 8-bit data). */ ++ png_read_row(png_ptr, local_row, NULL); ++ ++ /* Copy from local_row to user buffer. */ ++ memcpy(output_row, local_row, (size_t)row_bytes); ++ output_row += row_bytes; ++ } ++ } ++ ++ return 1; ++} ++ + /* Just the row reading part of png_image_read. */ + static int + png_image_read_composite(png_voidp argument) +@@ -3547,6 +3595,7 @@ png_image_read_direct(png_voidp argument) + int linear = (format & PNG_FORMAT_FLAG_LINEAR) != 0; + int do_local_compose = 0; + int do_local_background = 0; /* to avoid double gamma correction bug */ ++ int do_local_scale = 0; /* for interlaced 16-to-8 bit conversion */ + int passes = 0; + + /* Add transforms to ensure the correct output format is produced then check +@@ -3680,8 +3729,16 @@ png_image_read_direct(png_voidp argument) + png_set_expand_16(png_ptr); + + else /* 8-bit output */ ++ { + png_set_scale_16(png_ptr); + ++ /* For interlaced images, use local_row buffer to avoid overflow ++ * in png_combine_row() which writes using IHDR bit-depth. ++ */ ++ if (png_ptr->interlaced != 0) ++ do_local_scale = 1; ++ } ++ + change &= ~PNG_FORMAT_FLAG_LINEAR; + } + +@@ -3957,6 +4014,24 @@ png_image_read_direct(png_voidp argument) + return result; + } + ++ else if (do_local_scale != 0) ++ { ++ /* For interlaced 16-to-8 conversion, use an intermediate row buffer ++ * to avoid buffer overflows in png_combine_row. The local_row is sized ++ * for the transformed (8-bit) output, preventing the overflow that would ++ * occur if png_combine_row wrote 16-bit data directly to the user buffer. ++ */ ++ int result; ++ png_voidp row = png_malloc(png_ptr, png_get_rowbytes(png_ptr, info_ptr)); ++ ++ display->local_row = row; ++ result = png_safe_execute(image, png_image_read_direct_scaled, display); ++ display->local_row = NULL; ++ png_free(png_ptr, row); ++ ++ return result; ++ } ++ + else + { + png_alloc_size_t row_bytes = (png_alloc_size_t)display->row_bytes; +@@ -4040,20 +4115,6 @@ png_image_finish_read(png_imagep image, png_const_colorp background, + int result; + png_image_read_control display; + +- /* Reject bit depth mismatches to avoid buffer overflows. */ +- png_uint_32 ihdr_bit_depth = +- image->opaque->png_ptr->bit_depth; +- int requested_linear = +- (image->format & PNG_FORMAT_FLAG_LINEAR) != 0; +- if (ihdr_bit_depth == 16 && !requested_linear) +- return png_image_error(image, +- "png_image_finish_read: " +- "16-bit PNG must use 16-bit output format"); +- if (ihdr_bit_depth < 16 && requested_linear) +- return png_image_error(image, +- "png_image_finish_read: " +- "8-bit PNG must not use 16-bit output format"); +- + memset(&display, 0, (sizeof display)); + display.image = image; + display.buffer = buffer; diff --git a/SOURCES/libpng-1.6-CVE-2025-66293_p1of2.patch b/SOURCES/libpng-1.6-CVE-2025-66293_p1of2.patch new file mode 100644 index 0000000..fa24ae6 --- /dev/null +++ b/SOURCES/libpng-1.6-CVE-2025-66293_p1of2.patch @@ -0,0 +1,21 @@ +diff --git a/pngread.c b/pngread.c +index 79917daaaf..ab62edd9d8 100644 +--- a/pngread.c ++++ b/pngread.c +@@ -3273,9 +3273,14 @@ png_image_read_composite(png_voidp argument) + component += (255-alpha)*png_sRGB_table[outrow[c]]; + + /* So 'component' is scaled by 255*65535 and is +- * therefore appropriate for the sRGB to linear +- * conversion table. ++ * therefore appropriate for the sRGB-to-linear ++ * conversion table. Clamp to the valid range ++ * as a defensive measure against an internal ++ * libpng bug where the data is sRGB rather than ++ * linear premultiplied. + */ ++ if (component > 255*65535) ++ component = 255*65535; + component = PNG_sRGB_FROM_LINEAR(component); + } + diff --git a/SOURCES/libpng-1.6-CVE-2025-66293_p2of2.patch b/SOURCES/libpng-1.6-CVE-2025-66293_p2of2.patch new file mode 100644 index 0000000..4ce005b --- /dev/null +++ b/SOURCES/libpng-1.6-CVE-2025-66293_p2of2.patch @@ -0,0 +1,88 @@ +diff --git a/pngread.c b/pngread.c +index ab62edd9d8..f8ca2b7e31 100644 +--- a/pngread.c ++++ b/pngread.c +@@ -3207,6 +3207,7 @@ png_image_read_composite(png_voidp argument) + ptrdiff_t step_row = display->row_bytes; + unsigned int channels = + (image->format & PNG_FORMAT_FLAG_COLOR) != 0 ? 3 : 1; ++ int optimize_alpha = (png_ptr->flags & PNG_FLAG_OPTIMIZE_ALPHA) != 0; + int pass; + + for (pass = 0; pass < passes; ++pass) +@@ -3263,25 +3264,44 @@ png_image_read_composite(png_voidp argument) + + if (alpha < 255) /* else just use component */ + { +- /* This is PNG_OPTIMIZED_ALPHA, the component value +- * is a linear 8-bit value. Combine this with the +- * current outrow[c] value which is sRGB encoded. +- * Arithmetic here is 16-bits to preserve the output +- * values correctly. +- */ +- component *= 257*255; /* =65535 */ +- component += (255-alpha)*png_sRGB_table[outrow[c]]; +- +- /* So 'component' is scaled by 255*65535 and is +- * therefore appropriate for the sRGB-to-linear +- * conversion table. Clamp to the valid range +- * as a defensive measure against an internal +- * libpng bug where the data is sRGB rather than +- * linear premultiplied. +- */ +- if (component > 255*65535) +- component = 255*65535; +- component = PNG_sRGB_FROM_LINEAR(component); ++ if (optimize_alpha != 0) ++ { ++ /* This is PNG_OPTIMIZED_ALPHA, the component value ++ * is a linear 8-bit value. Combine this with the ++ * current outrow[c] value which is sRGB encoded. ++ * Arithmetic here is 16-bits to preserve the output ++ * values correctly. ++ */ ++ component *= 257*255; /* =65535 */ ++ component += (255-alpha)*png_sRGB_table[outrow[c]]; ++ ++ /* Clamp to the valid range to defend against ++ * unforeseen cases where the data might be sRGB ++ * instead of linear premultiplied. ++ * (Belt-and-suspenders for GitHub Issue #764.) ++ */ ++ if (component > 255*65535) ++ component = 255*65535; ++ ++ /* So 'component' is scaled by 255*65535 and is ++ * therefore appropriate for the sRGB-to-linear ++ * conversion table. ++ */ ++ component = PNG_sRGB_FROM_LINEAR(component); ++ } ++ else ++ { ++ /* Compositing was already done on the palette ++ * entries. The data is sRGB premultiplied on black. ++ * Composite with the background in sRGB space. ++ * This is not gamma-correct, but matches what was ++ * done to the palette. ++ */ ++ png_uint_32 background = outrow[c]; ++ component += ((255-alpha) * background + 127) / 255; ++ if (component > 255) ++ component = 255; ++ } + } + + outrow[c] = (png_byte)component; +diff --git a/pngrtran.c b/pngrtran.c +index 2f52022551..507d11381e 100644 +--- a/pngrtran.c ++++ b/pngrtran.c +@@ -1843,6 +1843,7 @@ png_init_read_transformations(png_structrp png_ptr) + * transformations elsewhere. + */ + png_ptr->transformations &= ~(PNG_COMPOSE | PNG_GAMMA); ++ png_ptr->flags &= ~PNG_FLAG_OPTIMIZE_ALPHA; + } /* color_type == PNG_COLOR_TYPE_PALETTE */ + + /* if (png_ptr->background_gamma_type!=PNG_BACKGROUND_GAMMA_UNKNOWN) */ diff --git a/SOURCES/libpng-CVE-2018-13785.patch b/SOURCES/libpng-CVE-2018-13785.patch new file mode 100644 index 0000000..5fee972 --- /dev/null +++ b/SOURCES/libpng-CVE-2018-13785.patch @@ -0,0 +1,34 @@ +From 9821583a771bfe2c75b7449d8ff83cb348291b3f Mon Sep 17 00:00:00 2001 +From: Cosmin Truta +Date: Sun, 17 Jun 2018 22:56:29 -0400 +Subject: [PATCH] Fix the calculation of row_factor in png_check_chunk_length + +(Bug report by Thuan Pham, SourceForge issue #278) +--- + pngrutil.c | 9 ++++++--- + 1 file changed, 6 insertions(+), 3 deletions(-) + +diff --git a/pngrutil.c b/pngrutil.c +index 8692933..eab2973 100644 +--- a/pngrutil.c ++++ b/pngrutil.c +@@ -3149,10 +3149,13 @@ png_check_chunk_length(png_const_structrp png_ptr, const png_uint_32 length) + { + png_alloc_size_t idat_limit = PNG_UINT_31_MAX; + size_t row_factor = +- (png_ptr->width * png_ptr->channels * (png_ptr->bit_depth > 8? 2: 1) +- + 1 + (png_ptr->interlaced? 6: 0)); ++ (size_t)png_ptr->width ++ * (size_t)png_ptr->channels ++ * (png_ptr->bit_depth > 8? 2: 1) ++ + 1 ++ + (png_ptr->interlaced? 6: 0); + if (png_ptr->height > PNG_UINT_32_MAX/row_factor) +- idat_limit=PNG_UINT_31_MAX; ++ idat_limit = PNG_UINT_31_MAX; + else + idat_limit = png_ptr->height * row_factor; + row_factor = row_factor > 32566? 32566 : row_factor; +-- +2.17.1 + diff --git a/SOURCES/libpng-coverity.patch b/SOURCES/libpng-coverity.patch new file mode 100644 index 0000000..053a954 --- /dev/null +++ b/SOURCES/libpng-coverity.patch @@ -0,0 +1,12 @@ +diff --git a/libpng-config.in b/libpng-config.in +index 3739eb9..7f6b2cc 100644 +--- a/libpng-config.in ++++ b/libpng-config.in +@@ -13,7 +13,6 @@ + + version=`pkg-config --modversion libpng` + prefix=`pkg-config --variable prefix libpng` +-exec_prefix=`pkg-config --variable exec_prefix libpng` + libdir=`pkg-config --variable libdir libpng` + includedir=`pkg-config --variable includedir libpng` + libs="-lpng@PNGLIB_MAJOR@@PNGLIB_MINOR@" diff --git a/SOURCES/libpng-fix-arm-neon.patch b/SOURCES/libpng-fix-arm-neon.patch new file mode 100644 index 0000000..e424957 --- /dev/null +++ b/SOURCES/libpng-fix-arm-neon.patch @@ -0,0 +1,39 @@ +diff --git a/configure.ac b/configure.ac +index 4fb0778..930bf50 100644 +--- a/configure.ac ++++ b/configure.ac +@@ -283,17 +283,21 @@ AC_ARG_ENABLE([arm-neon], + [case "$enableval" in + no|off) + # disable the default enabling on __ARM_NEON__ systems: ++ AC_DEFINE([PNG_ARM_NEON], [], [ARM NEON support]) + AC_DEFINE([PNG_ARM_NEON_OPT], [0], + [Disable ARM Neon optimizations]) + # Prevent inclusion of the assembler files below: + enable_arm_neon=no;; + check) ++ AC_DEFINE([PNG_ARM_NEON], [], [ARM NEON support]) + AC_DEFINE([PNG_ARM_NEON_CHECK_SUPPORTED], [], + [Check for ARM Neon support at run-time]);; + api) ++ AC_DEFINE([PNG_ARM_NEON], [], [ARM NEON support]) + AC_DEFINE([PNG_ARM_NEON_API_SUPPORTED], [], + [Turn on ARM Neon optimizations at run-time]);; + yes|on) ++ AC_DEFINE([PNG_ARM_NEON], [], [ARM NEON support]) + AC_DEFINE([PNG_ARM_NEON_OPT], [2], + [Enable ARM Neon optimizations]) + AC_MSG_WARN([--enable-arm-neon: please specify 'check' or 'api', if] +diff --git a/pngpriv.h b/pngpriv.h +index 1997503..789206f 100644 +--- a/pngpriv.h ++++ b/pngpriv.h +@@ -125,7 +125,7 @@ + * associated assembler code, pass --enable-arm-neon=no to configure + * or put -DPNG_ARM_NEON_OPT=0 in CPPFLAGS. + */ +-# if (defined(__ARM_NEON__) || defined(__ARM_NEON)) && \ ++# if defined(PNG_ARM_NEON) && (defined(__ARM_NEON__) || defined(__ARM_NEON)) && \ + defined(PNG_ALIGNED_MEMORY_SUPPORTED) + # define PNG_ARM_NEON_OPT 2 + # else diff --git a/SOURCES/libpng-multilib.patch b/SOURCES/libpng-multilib.patch new file mode 100644 index 0000000..c99c765 --- /dev/null +++ b/SOURCES/libpng-multilib.patch @@ -0,0 +1,23 @@ +Use pkg-config to report libpng version and installation directories. + + +diff -Naur libpng-1.5.5.orig/libpng-config.in libpng-1.5.5/libpng-config.in +--- libpng-1.5.5.orig/libpng-config.in 2011-09-22 09:40:23.000000000 -0400 ++++ libpng-1.5.5/libpng-config.in 2011-10-05 01:03:32.335435187 -0400 +@@ -11,11 +11,11 @@ + + # Modeled after libxml-config. + +-version="@PNGLIB_VERSION@" +-prefix="@prefix@" +-exec_prefix="@exec_prefix@" +-libdir="@libdir@" +-includedir="@includedir@/libpng@PNGLIB_MAJOR@@PNGLIB_MINOR@" ++version=`pkg-config --modversion libpng` ++prefix=`pkg-config --variable prefix libpng` ++exec_prefix=`pkg-config --variable exec_prefix libpng` ++libdir=`pkg-config --variable libdir libpng` ++includedir=`pkg-config --variable includedir libpng` + libs="-lpng@PNGLIB_MAJOR@@PNGLIB_MINOR@" + all_libs="-lpng@PNGLIB_MAJOR@@PNGLIB_MINOR@ @LIBS@" + I_opts="-I${includedir}" diff --git a/SOURCES/pngusr.dfa b/SOURCES/pngusr.dfa new file mode 100644 index 0000000..02e484d --- /dev/null +++ b/SOURCES/pngusr.dfa @@ -0,0 +1,4 @@ +# However, the default defaults seem a tad too restrictive for general +# purpose use, so back them off a little. +setting USER_CHUNK_CACHE_MAX default 1000 +setting USER_CHUNK_MALLOC_MAX default 1000000000 diff --git a/SPECS/mingw-libpng.spec b/SPECS/mingw-libpng.spec index 52ee012..09a2b07 100644 --- a/SPECS/mingw-libpng.spec +++ b/SPECS/mingw-libpng.spec @@ -1,19 +1,31 @@ %?mingw_package_header Name: mingw-libpng -Version: 1.6.29 -Release: 4%{?dist} +Version: 1.6.34 +Release: 1%{?dist} Summary: MinGW Windows Libpng library License: zlib URL: http://www.libpng.org/pub/png/ # Note: non-current tarballs get moved to the history/ subdirectory, # so look there if you fail to retrieve the version you want -Source0: ftp://ftp.simplesystems.org/pub/png/src/libpng16/libpng-%{version}.tar.xz +Source0: https://ftp-osl.osuosl.org/pub/libpng/src/libpng16/libpng-%{version}.tar.xz +Source1: pngusr.dfa +Patch0: libpng-multilib.patch +Patch1: libpng-fix-arm-neon.patch +Patch2: libpng-CVE-2018-13785.patch +Patch3: libpng-coverity.patch +Patch4: libpng-1.6-CVE-2025-64720.patch +Patch5: libpng-1.6-CVE-2025-65018_p1of2.patch +Patch6: libpng-1.6-CVE-2025-65018_p2of2.patch +Patch7: libpng-1.6-CVE-2025-66293_p1of2.patch +Patch8: libpng-1.6-CVE-2025-66293_p2of2.patch BuildArch: noarch ExclusiveArch: %{ix86} x86_64 +BuildRequires: zlib-devel +BuildRequires: autoconf automake libtool BuildRequires: mingw32-filesystem >= 95 BuildRequires: mingw32-gcc BuildRequires: mingw32-binutils @@ -69,7 +81,20 @@ This package contains static cross-compiled libraries. %prep %setup -q -n libpng-%{version} +# Provide pngusr.dfa for build. +cp -p %{SOURCE1} . +%patch -P 0 -p1 +%patch -P 1 -p1 -b .arm +%patch -P 2 -p1 -b .CVE-2018-13785 +%patch -P 3 -p1 -b .coverity +%patch -P 4 -p1 -b .CVE-2025-64720 +%patch -P 5 -p1 -b .CVE-2025-65018_p1of2 +%patch -P 6 -p1 -b .CVE-2025-65018_p2of2 +%patch -P 7 -p1 -b .CVE-2025-66293_p1of2 +%patch -P 8 -p1 -b .CVE-2025-66293_p2of2 + +autoreconf -vif %build %mingw_configure @@ -134,6 +159,14 @@ rm -rf $RPM_BUILD_ROOT%{mingw64_mandir} %changelog +* Sat Dec 27 2025 Lili Zhu - 1.6.34-1 +- Rebase to version 1.6.34 +- Fix the following CVEs + CVE-2025-64720 CVE-2025-65018 CVE-2025-66293 +- Resolves: RHEL-131458 +- Resolves: RHEL-131471 +- Resolves: RHEL-133229 + * Tue Aug 14 2018 Victor Toso - 1.6.29-4 - ExclusiveArch: i686, x86_64 - Related: rhbz#1615874