libsdl3-image_3.2.4+ds-1+deb13u1_source.changes ACCEPTED into proposed-updates->stable-new
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Sun Aug 23 15:23:59 BST 2026
Thank you for your contribution to Debian.
Mapping trixie to stable.
Mapping stable to proposed-updates.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sun, 23 Aug 2026 14:44:26 +0100
Source: libsdl3-image
Architecture: source
Version: 3.2.4+ds-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian SDL packages maintainers <pkg-sdl-maintainers at lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv at debian.org>
Changes:
libsdl3-image (3.2.4+ds-1+deb13u1) trixie; urgency=medium
.
* d/control, d/gbp.conf: Branch for trixie
* d/patches: Add a malformed-image parser robustness fix from 3.4.2:
- d/p/Fixed-out-of-bounds-read-in-XCF-image-loader-thanks-Sebas.patch:
Avoid an out-of-bounds read when loading invalid XCF images
(CVE-2026-35444, same issue as #1133010 in libsdl2-image)
* d/patches: Add selected upstream malformed-image parser robustness
fixes from 3.4.4:
- d/p/xpm-Remove-QUICK_COLORHASH-replace-it-with-inline-code-th.patch:
Check XPM colour hash entries before use
- d/p/Fix-heap-buffer-overflow-WRITE-in-LBM-palette-CWE-122.patch
Avoid an out-of-bounds write when parsing LBM images
- d/p/Fix-heap-underflow-WRITE-in-XCF-read_string-CWE-787.patch
Avoid an out-of-bounds write if XCF files contain a zero-length string
- d/p/Fix-heap-buffer-overflow-READ-in-XCF-do_layer_surface-CWE.patch,
d/p/xcf-Added-an-SDL_SetError-when-rejecting-out-of-bounds-ti.patch:
Avoid an out-of-bounds read when parsing XCF file tile data, and
report the resulting error correctly
- d/p/Fix-heap-buffer-overflow-READ-in-XCF-RLE-decoder-CWE-122.patch:
Avoid an out-of-bounds read when parsing XCF files with RLE encoding
- d/p/xcf-fix-null-pointer-dereference-when-read_xcf_hierarchy-.patch:
Check XCF hierarchy read failures before dereferencing
- d/p/tga-reject-images-with-zero-width-or-height.patch:
Reject zero-sized TGA images as invalid
- d/p/Fixed-out-of-bound-read-in-GIF-decoder.patch:
Avoid out-of-bounds reads in the GIF decoder
* d/patches: Add an additional parser robustness fix from upstream git:
- d/p/IMG_xcf.c-read_string-add-back-the-positive-string-size-c.patch
Harden XCF parsing against extremely long strings
* Thanks to Aquila Macedo Costa
Checksums-Sha1:
42ef0cdf34aa9ed4ae927b6ccd342f697528d562 2959 libsdl3-image_3.2.4+ds-1+deb13u1.dsc
e543acce9b2074859e9fd127468fbd29fc4994e5 17824 libsdl3-image_3.2.4+ds-1+deb13u1.debian.tar.xz
8e5dfc32a019f6008b2164559b2fdab6973d9103 548220 libsdl3-image_3.2.4+ds-1+deb13u1.git.tar.xz
86edba8936a1502162a304c2e8188d48fd52065c 17728 libsdl3-image_3.2.4+ds-1+deb13u1_source.buildinfo
Checksums-Sha256:
4a0ee9b639f2f8b2d20d3491d65a61e0a582a598909ab27a9227711e52456892 2959 libsdl3-image_3.2.4+ds-1+deb13u1.dsc
edd4d666e35f7fad92a502945e2b8426b9c53cf506667790fe1f6674b4cc798e 17824 libsdl3-image_3.2.4+ds-1+deb13u1.debian.tar.xz
adb67ae4728a04edc37c5e2217b06bfb4af20dc993ef135d50169393e9485958 548220 libsdl3-image_3.2.4+ds-1+deb13u1.git.tar.xz
953204e14509e313619a7f567120793de72246f3ac6567bc7c8fd32ac02b71bd 17728 libsdl3-image_3.2.4+ds-1+deb13u1_source.buildinfo
Files:
d54c01a77f56d1171fbdbc4553f3ed0f 2959 libs optional libsdl3-image_3.2.4+ds-1+deb13u1.dsc
0df587fad5abf358a148daa546ad1e4a 17824 libs optional libsdl3-image_3.2.4+ds-1+deb13u1.debian.tar.xz
766105fa33ac2f9462807e25245786db 548220 libs optional libsdl3-image_3.2.4+ds-1+deb13u1.git.tar.xz
37b2a412aa3ce783f38f5856c3eb7686 17728 libs optional libsdl3-image_3.2.4+ds-1+deb13u1_source.buildinfo
Git-Tag-Info: tag=83233dca939306a2afb4086b1d4fef52ad3026f5 fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv at debian.org>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqK/ZAACgkQYG0ITkaD
wHlIgBAApB7/6wA+DTveKmWhgej1FCSJIHGe/R10V/4oG5WjEG1OsH3gKVcKyiWf
c+/rF6k76clSHsWYoVqVtfpC9tWp0TLGHHdyeG59tyG2ji9aPmv+cWBm7z41nyZC
umMVZsT2NBUZarD1TpnGLZHOwQqIzKKEcX8sczORYwn3QkzN4b30cSmLJ05aZca9
t3S3AUBeatJ/pe+U+rJrpbrJSLcq/2PbIOY6RFYLm7lASCfPRCoGissHfqxHLnPA
nAOA6qemP8zlIVXVc/os991tZZm7EoG7FVlv9wFpqR4Aaqo4xwIxmcB1Xb0rwOe8
6pf83c19wYkQ94+jdUbnR5NqrrRft7dUlNlCS0IHA9iwqHqaMVCdTVj0Hck9OxUn
fojiZgmIFdzvy4o3pmqChNTQURVKC+KmhcG7IK2aDc+awC1fY1zVYvVlE7kt9tC2
tFwgqunvKGII4e3nR2iASMpLRwRZsbIsoBuPvsYMtw/Rt3u56/jOkm95eFkH0CeT
WmSfSWXUfjRGL+h5Zcv/kHordwUBaC60f64Hn57n4oX8Gc4TRArKGhKpDcqnVJkO
wmaVyFtiX45y9fhTi6aHpvLhoZHKYP10bjh4/NO6C8aw/+75RlZ5v6uubeONS7J7
lO4vCJkZMgBIUAfBIxdYhY5FOkNq3+n4AGL+obdd6MPBaWumV48=
=cmjb
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-sdl-maintainers/attachments/20260823/cc0f8d0e/attachment.sig>
More information about the Pkg-sdl-maintainers
mailing list