Draft worked example — real CVE and named products, but not an official Servomex advisory

SMX-PSA-2026-001 — draft example

libpng vulnerability in QNX 6.5-based products

This worked example uses CVE-2026-25646 and the Servomex products identified as affected. Exact product release versions, part numbers and download links remain placeholders pending Engineering and PSIRT approval.

Downloadable advisoryThis PDF is a draft example snapshot. A published web page would remain the authoritative, current version.
Download PDF

Customer action — proposed wording

Download and install the approved product software version listed below

“Customer action” tells the customer what to do. “Fix available” is the separate remediation status. The exact Servomex versions and download links must be inserted before this example could become a real advisory.

Summary

libpng versions before 1.6.55 contain an out-of-bounds read in the png_set_quantize() API. With no histogram and a palette containing more than twice the maximum colours supported by the display, a valid PNG image can cause an infinite loop that reads beyond an internal heap buffer. This example assumes that the affected library supplied in the relevant QNX 6.5 software image is present in the products listed below.

Product applicability and customer action

Product or product range / model / partPlatform / componentAffected versionsAssessment / remediationCustomer action
2500F
2500F
Confirm applicable part numbers with Servomex
QNX 6.5 variants — exact scope to be confirmed
libpng supplied within the QNX 6.5 software image
Product releases containing an affected libpng version — exact range to be confirmedKnown affected
Fix available
Fixed/recommended: Approved Servomex release — insert version before publication
Download and install this version.
Laser 3 Plus
Laser 3 Plus
Confirm applicable part numbers with Servomex
QNX 6.5 variants — exact scope to be confirmed
libpng supplied within the QNX 6.5 software image
Product releases containing an affected libpng version — exact range to be confirmedKnown affected
Fix available
Fixed/recommended: Approved Servomex release — insert version before publication
Download and install this version.
Multi TX
Multi TX
Confirm applicable part numbers with Servomex
QNX 6.5 variants — exact scope to be confirmed
libpng supplied within the QNX 6.5 software image
Product releases containing an affected libpng version — exact range to be confirmedKnown affected
Fix available
Fixed/recommended: Approved Servomex release — insert version before publication
Download and install this version.
4100
4100
Confirm applicable part numbers with Servomex
QNX 6.5 variants — exact scope to be confirmed
libpng supplied within the QNX 6.5 software image
Product releases containing an affected libpng version — exact range to be confirmedKnown affected
Fix available
Fixed/recommended: Approved Servomex release — insert version before publication
Download and install this version.
4200
4200
Confirm applicable part numbers with Servomex
QNX 6.5 variants — exact scope to be confirmed
libpng supplied within the QNX 6.5 software image
Product releases containing an affected libpng version — exact range to be confirmedKnown affected
Fix available
Fixed/recommended: Approved Servomex release — insert version before publication
Download and install this version.
Multi Gas 4900
Multi Gas 4900
Confirm applicable part numbers with Servomex
QNX 6.5 variants — exact scope to be confirmed
libpng supplied within the QNX 6.5 software image
Product releases containing an affected libpng version — exact range to be confirmedKnown affected
Fix available
Fixed/recommended: Approved Servomex release — insert version before publication
Download and install this version.
DF150E
DF150E
Confirm applicable part numbers with Servomex
QNX 6.5 variants — exact scope to be confirmed
libpng supplied within the QNX 6.5 software image
Product releases containing an affected libpng version — exact range to be confirmedKnown affected
Fix available
Fixed/recommended: Approved Servomex release — insert version before publication
Download and install this version.
DF300E
DF300E
Confirm applicable part numbers with Servomex
QNX 6.5 variants — exact scope to be confirmed
libpng supplied within the QNX 6.5 software image
Product releases containing an affected libpng version — exact range to be confirmedKnown affected
Fix available
Fixed/recommended: Approved Servomex release — insert version before publication
Download and install this version.

Before publication, Engineering must replace every placeholder with an approved product release, precise affected-version range, applicable part numbers and a working download or support link.

Vulnerability details

CWE
CWE-125: Out-of-bounds Read
CNA CVSS
7.0 High — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Known exploitation
No known exploitation — confirm before publication
Attack requirements
The product must call the affected API while processing attacker-controlled PNG palette data; the available Servomex input path must be validated per product.
Remediation status
Fix available — product software update incorporating the applicable fix

Description

Certain valid PNG palettes can cause png_set_quantize() to enter an infinite loop and read beyond an internal heap-allocated buffer when no histogram is supplied.

Potential impact

Successful exploitation could disclose process memory or cause the process handling the image to fail. Servomex must assess the credible product-level consequence and any effect on measurement, availability or safety before publication.

Temporary mitigation

  1. Do not transfer or process PNG files from untrusted sources.
  2. Restrict product access and file-transfer mechanisms to authorised users and systems.
  3. Contact Servomex Support if you cannot determine whether your installed product release is affected.

Remediation

The final advisory should identify an approved Servomex software release for each affected product. The customer-facing instruction should then be direct: Download and install this version. Any restart, downtime, configuration restoration or recalibration requirements should appear beside the download instructions.

Revision history

VersionDateChange
2.1-draft1 September 2026Corrected the worked example to CVE-2026-25646 and aligned the technical details and severity
2.0-draft1 September 2026Replaced the fictional issue with a worked libpng/QNX 6.5 portfolio example and clarified customer-action wording
1.11 September 2026Initial fictional multi-product format demonstration

Contact

Potential vulnerabilities should be reported to psirt@servomex.com in accordance with the Servomex Vulnerability Disclosure Policy.