trixie-pu: package libsdl2-image/2.8.8+dfsg-1+deb13u1

Simon McVittie smcv at debian.org
Sun Aug 23 15:11:03 BST 2026


Control: tags -1 - moreinfo

[ Reason ]
Fix CVE-2026-35444 and various other out-of-bounds accesses when parsing 
malformed/crafted image files

[ Impact ]
If not fixed, games/applications that load untrusted images using 
SDL2_image could be subject to denial-of-service (crash) or possibly 
exploitable.

[ Tests ]
autopkgtest (automated smoke-tests loading images in various formats) 
passes. Some sample games from trixie that depend on this library 
(assaultcube, wesnoth) appear to run normally. As with SDL3_image, I 
haven't attempted to load malformed/crafted/malicious images.

A test-build (equivalent except for the changelog) is available from 
<https://people.debian.org/~smcv/13.7/libsdl2-image/testbuild/>.

[ Risks ]
Could regress image loading in SDL2 games, especially in weird/rare 
formats. I suspect that in practice, none of our games/applications rely 
on being able to load the affected formats (*maybe* GIF and TGA).

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
All changes are robustness fixes from upstream. Most are fixed in 3.4.2 
or 3.4.4 upstream. One is not in an upstream release yet, I backported 
it into forky already.

[ Other info ]
Related to https://bugs.debian.org/1145180 for libsdl3-image, a newer 
branch of the same codebase.

Compared with the earlier proposal from Aquila Macedo Costa, this one 
addresses all known out-of-bounds accesses, not just the one that (for 
whatever reason) had a CVE ID allocated upstream.
-------------- next part --------------
A non-text attachment was scrubbed...
Name: libsdl2-image_2.8.8+dfsg-1+deb13u1.diff
Type: text/x-diff
Size: 39969 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-sdl-maintainers/attachments/20260823/3cb175d5/attachment-0001.diff>


More information about the Pkg-sdl-maintainers mailing list