libsdl2-image_2.8.8+dfsg-1+deb13u1_source.changes ACCEPTED into proposed-updates->stable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Sun Aug 23 15:49:34 BST 2026


Thank you for your contribution to Debian.

Mapping trixie to stable.
Mapping stable to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 23 Aug 2026 14:45:36 +0100
Source: libsdl2-image
Architecture: source
Version: 2.8.8+dfsg-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian SDL packages maintainers <pkg-sdl-maintainers at lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv at debian.org>
Closes: 1133010
Changes:
 libsdl2-image (2.8.8+dfsg-1+deb13u1) trixie; urgency=medium
 .
   [ Aquila Macedo Costa ]
   * d/p/Fixed-out-of-bounds-read-in-XCF-image-loader-thanks-Sebas.patch:
     Import upstream patch for CVE-2026-35444 (Closes: #1133010)
   * d/patches: Add selected upstream malformed-image parser robustness fixes:
     - d/p/xpm-Remove-QUICK_COLORHASH-replace-it-with-inline-code-th.patch:
       check XPM color hash entries before use
     - d/p/Fix-heap-buffer-overflow-WRITE-in-LBM-palette-CWE-122.patch:
       fix LBM palette overflow
     - d/p/xcf-Fix-heap-buffer-overflow-READ-in-XCF-RLE-decoder-CWE-.patch:
       add XCF RLE decoder bounds checks
     - d/p/Fix-heap-buffer-overflow-READ-in-XCF-do_layer_surface-CWE.patch,
       d/p/xcf-Added-an-SDL_SetError-when-rejecting-out-of-bounds-ti.patch:
       add XCF do_layer_surface tile bounds check, report invalid XCF tile data
       through SDL_SetError()
     - d/p/xcf-fix-null-pointer-dereference-when-read_xcf_hierarchy-.patch:
       check XCF hierarchy read failures before dereferencing
     - d/p/tga-reject-images-with-zero-width-or-height.patch:
       reject TGA images with zero width or height
     - d/p/Fixed-out-of-bound-read-in-GIF-decoder.patch:
       fix out-of-bounds reads in the GIF decoder
 .
   [ Simon McVittie ]
   * d/control, d/gbp.conf: Branch for trixie
   * d/patches: Improve patch metadata: add CVE ID, Debian bug number,
     upstream commit references, etc.
   * d/patches: Re-export patches with their mechanically-generated names and
     apply them in the same order that upstream did, to make it more obvious
     how this version compares with 2.8.12
   * d/patches: Add additional robustness fixes for parsing malformed images:
     - d/p/xcf-Permit-empty-strings-in-read_string.patch:
       Avoid an out-of-bounds write if XCF files contain a zero-length string
     - d/p/IMG_xcf.c-read_string-add-back-the-positive-string-size-c.patch:
       Harden XCF parsing against extremely long strings
Checksums-Sha1:
 3f290cc4c45460ca1bd889260ba33974a801482f 2800 libsdl2-image_2.8.8+dfsg-1+deb13u1.dsc
 f77ddec72ddfc4dd633f2877e316dc4f76bd6b80 17024 libsdl2-image_2.8.8+dfsg-1+deb13u1.debian.tar.xz
 be6fa2d6c35895bc21ed96699b389ac48773d411 550508 libsdl2-image_2.8.8+dfsg-1+deb13u1.git.tar.xz
 faf47e61670bd197a0841dfffb5567a326bed173 17736 libsdl2-image_2.8.8+dfsg-1+deb13u1_source.buildinfo
Checksums-Sha256:
 fc0e1b5c82432f9bb8a00e78433869a557f03af306fbbca1102c8adcddfab730 2800 libsdl2-image_2.8.8+dfsg-1+deb13u1.dsc
 5ac5b54d431e55d4ba6c0139b29a3bbf3579cc506ed9904c11cf830d6da8173e 17024 libsdl2-image_2.8.8+dfsg-1+deb13u1.debian.tar.xz
 13ae5163202f1be007ae6a6ccde3702f87f774671a05b6639f0498e599250b32 550508 libsdl2-image_2.8.8+dfsg-1+deb13u1.git.tar.xz
 ecf60ec8f6241da3cf71bc59dab18981a5227d914eabd717988ff85362a793d8 17736 libsdl2-image_2.8.8+dfsg-1+deb13u1_source.buildinfo
Files:
 b8f09909f7ccaac27bcb3da85b3ba5f8 2800 libs optional libsdl2-image_2.8.8+dfsg-1+deb13u1.dsc
 1f4a15ac9a5761d897bbf85f181ca4de 17024 libs optional libsdl2-image_2.8.8+dfsg-1+deb13u1.debian.tar.xz
 83fd07c0e0712d0e9c5f88557501b91c 550508 libs optional libsdl2-image_2.8.8+dfsg-1+deb13u1.git.tar.xz
 a176847270a8adca3cc34c0c32d43e13 17736 libs optional libsdl2-image_2.8.8+dfsg-1+deb13u1_source.buildinfo
Git-Tag-Info: tag=65dea864e465e9e20659c3dae3687002831e068a fp=7a073ad1ae694fa25bff62e5235c099d3eb33076
Git-Tag-Tagger: Simon McVittie <smcv at debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmqK/9UACgkQYG0ITkaD
wHmwihAAzwuzDKEZ3TvJcSWSQg2cZssH1YzqwT82q0CD/EO/UvNufGMycxNJf19T
5NM253cMLe295/g6doWQvvKQXxH9uht1ZRM2McmirN5s03LF9cdf4GyOY4cpYPsd
bwHRo+fD+EyomNuxRbFk3SO2uYb4oREwbBcg3vApNRWIVjIr0PwytuY7WBUc/tUa
aWhEOUo8HxE7oiNh/w2vcYLaRtnol3cIz3mTwA0+jw4LO7A8ciAs6ljQEvdMnFPo
oximprDEtyN8BiGVw9WHQqE/pzZERawEqDsQE0GRBDRbh///PW+Ahy9xfrRl1eC1
vRaLSorvc1EL6Se9xyn8cd7ID8xHORQVLhLVS7MFJZaqEBS0lAP3QDfCTJzwhom1
8OaQIWtvO0cWcDmx7b60MpTg3gpRDTMFq9rZJN3DfYfrcQ03xVG0KoI3V1NmUmXD
SnsP14B7CByBMzzOgibN0hLfLgZNAH6je0+2dX0PwRtHxckhmFd4l7fFEr5qXXs7
vNDsqXypV7YDoj8a8HXP2zjAPrTPqtMErJha3jqm8aG8SbdEJj9JRQylVGCLHkpQ
6oI50ZJvxWYhXoLG472XJWLXy3sKX1rKfvfapBwDv9mWiW8pmutxGkHzH3hcH625
be8JO3gexZU+Wtt/HWkrhTbnHECW9IqpqqSfGviz6z4FUKSYmyk=
=CvMc
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-sdl-maintainers/attachments/20260823/5a715488/attachment.sig>


More information about the Pkg-sdl-maintainers mailing list