From nobody Thu Mar 26 11:13:42 2026 X-Original-To: desktop@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4fhLkG3hsnz6WnBq for ; Thu, 26 Mar 2026 11:13:42 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R12" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4fhLkG1KD0z3Dmx for ; Thu, 26 Mar 2026 11:13:42 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1774523622; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1vf1c7ogYOtjtfZNhzFJd2ihgE9lcnVQloXM8mGQg+Q=; b=pbsjbX1qoVH9gk7H9lBdH52qJCzH36deB9Pul+lCCGXJHzW8a4FGXa9j+wh8N/UXAc0RMT 0J2Jawi7ps7MMEE95K6DMlYM1QpHyS5kjxpqjN9He7wHSTTbqnFd9HA/ujKsID3kSkAmR7 PVCbgSk9NqOvJf6Pilomsiia14iei+PNGoV4chQBYyzJzOAiY/2JYPVwGnwCCxUWrK7Stf jnRaGOi+Q4Qz7euQCPNSWuC8s73eBYRbv8JrGx74u2U0NvhEjSQJQ8150cZmYwN2ID6kHQ W8uPROW9UIYHc5p9hxXXSPKVmr3nHUx5ghjpDXCI+b8GmYrnUGWsNfxZOjdpsQ== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1774523622; a=rsa-sha256; cv=none; b=ej6tD1oINSlyksrxH/yyPrx/Ghwr5a9svwrIdqLwBj5tAGoa7ITUdT30eMSBqlDD/8QlnF MolIpv2diIgchJU3xLkrGn9L+KwCL4AksHkk20yu2g6SJlP/HOVOpHmuPGWT+qdpmNDUIu qlTiTrmK8koTTjXVXfDfDtPSN6vh0lRhkKd8DW7vvM9ILamJBqnF7/ganvppjXhEgdhxtT 5uMuBTVODF57EWMYTRdiSwAQg0yFZfwEX49oCpoGEzfV7Pv7kyoFulCWkMzgT3e7ebvqqY IPUV740TKiv8e49wB3SR8UN2alQoX4JpEWsiaXvx4wTdtCQ5sG28tisJfBNGXg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1774523622; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=1vf1c7ogYOtjtfZNhzFJd2ihgE9lcnVQloXM8mGQg+Q=; b=tdzm8WiJtXwF5iSCS04iKgk/vHhTZzY4wRlIpMeKlWsPJgYCSNL8CNBm5Jh4gp2eohvTFw e+LK6A0ZrFI0iqskBpHyvp5j5KKL1jkv+YECHwBJKCVJ4cAANxXoKLujJPSvM8uzbNGTD6 GVU7wn0PyatWkjHOEidZNRScDlSr3ZHGC4z6fEvkb9XGZUVRMFUvhV6QkHSu9FsJtfRWDt +SS8zWwkM5l0pdhEIUbNGQmW9yOGo/29Crz4DfvZlBs8pcfXFHtBKIAQ8hysDr09IQ8XmF newqG936YM/4F7UvvK1+KbBs0hfR/8BLgjtAOr9vyWdWRrsJbP7jQICE06AmBw== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4fhLkG0dj6zqDR for ; Thu, 26 Mar 2026 11:13:42 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 62QBDfdj050163 for ; Thu, 26 Mar 2026 11:13:41 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 62QBDfrc050162 for desktop@FreeBSD.org; Thu, 26 Mar 2026 11:13:41 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" From: bugzilla-noreply@freebsd.org To: desktop@FreeBSD.org Subject: maintainer-feedback requested: [Bug 294061] graphics/png: Security Update to 1.6.56 Date: Thu, 26 Mar 2026 11:13:42 +0000 X-Bugzilla-Type: request X-Bugzilla-Product: Ports & Packages X-Bugzilla-Component: Individual Port(s) X-Bugzilla-Version: Latest X-Bugzilla-Keywords: security X-Bugzilla-Severity: Affects Many People X-Bugzilla-Who: X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: desktop@FreeBSD.org X-Bugzilla-Flags: maintainer-feedback? Message-ID: In-Reply-To: References: X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Using and improving FreeBSD on the desktop List-Archive: https://lists.freebsd.org/archives/freebsd-desktop List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-desktop@FreeBSD.org MIME-Version: 1.0 Bugzilla Automation has asked freebsd-desktop (Team) for maintainer-feedback: Bug 294061: graphics/png: Security Update to 1.6.56 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D294061 --- Description --- As reported through oss-security mailing list with: "libpng 1.6.56: Two high-severity vulnerabilities fixed: CVE-2026-33416, CVE-2026-33636" https://www.openwall.com/lists/oss-security/2026/03/26/1 As I see it, libpng-1.6.56-apng.patch is not yet available, so the attached patch is only partially and building the ports is not possible yet.