trixie-pu: package libsdl2-image/2.8.8+dfsg-1+deb13u1
Simon McVittie
smcv at debian.org
Sun Aug 23 15:11:03 BST 2026
Control: tags -1 - moreinfo
[ Reason ]
Fix CVE-2026-35444 and various other out-of-bounds accesses when parsing
malformed/crafted image files
[ Impact ]
If not fixed, games/applications that load untrusted images using
SDL2_image could be subject to denial-of-service (crash) or possibly
exploitable.
[ Tests ]
autopkgtest (automated smoke-tests loading images in various formats)
passes. Some sample games from trixie that depend on this library
(assaultcube, wesnoth) appear to run normally. As with SDL3_image, I
haven't attempted to load malformed/crafted/malicious images.
A test-build (equivalent except for the changelog) is available from
<https://people.debian.org/~smcv/13.7/libsdl2-image/testbuild/>.
[ Risks ]
Could regress image loading in SDL2 games, especially in weird/rare
formats. I suspect that in practice, none of our games/applications rely
on being able to load the affected formats (*maybe* GIF and TGA).
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
All changes are robustness fixes from upstream. Most are fixed in 3.4.2
or 3.4.4 upstream. One is not in an upstream release yet, I backported
it into forky already.
[ Other info ]
Related to https://bugs.debian.org/1145180 for libsdl3-image, a newer
branch of the same codebase.
Compared with the earlier proposal from Aquila Macedo Costa, this one
addresses all known out-of-bounds accesses, not just the one that (for
whatever reason) had a CVE ID allocated upstream.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: libsdl2-image_2.8.8+dfsg-1+deb13u1.diff
Type: text/x-diff
Size: 39969 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-sdl-maintainers/attachments/20260823/3cb175d5/attachment-0001.diff>
More information about the Pkg-sdl-maintainers
mailing list