Permalink
CVE-2026-35444
7.1 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): Low (L)
Activity log
- Created suggestion
SDL_image has a heap buffer overflow READ via unchecked colormap index in XCF loader
SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.
References
-
https://github.com/libsdl-org/SDL_image/security/advisories/GHSA-gq8w-x74c-h6p7 x_refsource_CONFIRM
Affected products
SDL_image
- ==< 996bf12888925932daace576e09c3053410896f8
Matching in nixpkgs
pkgs.SDL_image
SDL image library
-
nixos-unstable 1.2.12-unstable-2025-11-06
- nixpkgs-unstable 1.2.12-unstable-2025-11-06
- nixos-unstable-small 1.2.12-unstable-2025-11-06
Package maintainers
-
@jansol Jan Solanti <jan.solanti@paivola.fi>
-
@LordGrimmauld Sören Bender <soeren@benjos.de>
-
@pbsds Peder Bergebakken Sundt <pbsds@hotmail.com>
-
@EvysGarden Evy Garden <evysgarden@protonmail.com>
-
@marcin-serwin Marcin Serwin <marcin@serwin.dev>