Customer action — proposed wording
Download and install the approved product software version listed below
“Customer action” tells the customer what to do. “Fix available” is the separate remediation status. The exact Servomex versions and download links must be inserted before this example could become a real advisory.
Summary
libpng versions before 1.6.55 contain an out-of-bounds read in the png_set_quantize() API. With no histogram and a palette containing more than twice the maximum colours supported by the display, a valid PNG image can cause an infinite loop that reads beyond an internal heap buffer. This example assumes that the affected library supplied in the relevant QNX 6.5 software image is present in the products listed below.
Product applicability and customer action
| Product or product range / model / part | Platform / component | Affected versions | Assessment / remediation | Customer action |
|---|---|---|---|---|
| 2500F 2500F Confirm applicable part numbers with Servomex | QNX 6.5 variants — exact scope to be confirmed libpng supplied within the QNX 6.5 software image | Product releases containing an affected libpng version — exact range to be confirmed | Known affected Fix available Fixed/recommended: Approved Servomex release — insert version before publication | Download and install this version. |
| Laser 3 Plus Laser 3 Plus Confirm applicable part numbers with Servomex | QNX 6.5 variants — exact scope to be confirmed libpng supplied within the QNX 6.5 software image | Product releases containing an affected libpng version — exact range to be confirmed | Known affected Fix available Fixed/recommended: Approved Servomex release — insert version before publication | Download and install this version. |
| Multi TX Multi TX Confirm applicable part numbers with Servomex | QNX 6.5 variants — exact scope to be confirmed libpng supplied within the QNX 6.5 software image | Product releases containing an affected libpng version — exact range to be confirmed | Known affected Fix available Fixed/recommended: Approved Servomex release — insert version before publication | Download and install this version. |
| 4100 4100 Confirm applicable part numbers with Servomex | QNX 6.5 variants — exact scope to be confirmed libpng supplied within the QNX 6.5 software image | Product releases containing an affected libpng version — exact range to be confirmed | Known affected Fix available Fixed/recommended: Approved Servomex release — insert version before publication | Download and install this version. |
| 4200 4200 Confirm applicable part numbers with Servomex | QNX 6.5 variants — exact scope to be confirmed libpng supplied within the QNX 6.5 software image | Product releases containing an affected libpng version — exact range to be confirmed | Known affected Fix available Fixed/recommended: Approved Servomex release — insert version before publication | Download and install this version. |
| Multi Gas 4900 Multi Gas 4900 Confirm applicable part numbers with Servomex | QNX 6.5 variants — exact scope to be confirmed libpng supplied within the QNX 6.5 software image | Product releases containing an affected libpng version — exact range to be confirmed | Known affected Fix available Fixed/recommended: Approved Servomex release — insert version before publication | Download and install this version. |
| DF150E DF150E Confirm applicable part numbers with Servomex | QNX 6.5 variants — exact scope to be confirmed libpng supplied within the QNX 6.5 software image | Product releases containing an affected libpng version — exact range to be confirmed | Known affected Fix available Fixed/recommended: Approved Servomex release — insert version before publication | Download and install this version. |
| DF300E DF300E Confirm applicable part numbers with Servomex | QNX 6.5 variants — exact scope to be confirmed libpng supplied within the QNX 6.5 software image | Product releases containing an affected libpng version — exact range to be confirmed | Known affected Fix available Fixed/recommended: Approved Servomex release — insert version before publication | Download and install this version. |
Before publication, Engineering must replace every placeholder with an approved product release, precise affected-version range, applicable part numbers and a working download or support link.
Vulnerability details
- CWE
- CWE-125: Out-of-bounds Read
- CNA CVSS
- 7.0 High — CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
- Known exploitation
- No known exploitation — confirm before publication
- Attack requirements
- The product must call the affected API while processing attacker-controlled PNG palette data; the available Servomex input path must be validated per product.
- Remediation status
- Fix available — product software update incorporating the applicable fix
Description
Certain valid PNG palettes can cause png_set_quantize() to enter an infinite loop and read beyond an internal heap-allocated buffer when no histogram is supplied.
Potential impact
Successful exploitation could disclose process memory or cause the process handling the image to fail. Servomex must assess the credible product-level consequence and any effect on measurement, availability or safety before publication.
Temporary mitigation
- Do not transfer or process PNG files from untrusted sources.
- Restrict product access and file-transfer mechanisms to authorised users and systems.
- Contact Servomex Support if you cannot determine whether your installed product release is affected.
Remediation
The final advisory should identify an approved Servomex software release for each affected product. The customer-facing instruction should then be direct: Download and install this version. Any restart, downtime, configuration restoration or recalibration requirements should appear beside the download instructions.
Revision history
| Version | Date | Change |
|---|---|---|
| 2.1-draft | 1 September 2026 | Corrected the worked example to CVE-2026-25646 and aligned the technical details and severity |
| 2.0-draft | 1 September 2026 | Replaced the fictional issue with a worked libpng/QNX 6.5 portfolio example and clarified customer-action wording |
| 1.1 | 1 September 2026 | Initial fictional multi-product format demonstration |
Contact
Potential vulnerabilities should be reported to psirt@servomex.com in accordance with the Servomex Vulnerability Disclosure Policy.