Описание
SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| libsdl2-image | fixed | 2.8.10+dfsg-1 | package | |
| libsdl2-image | no-dsa | trixie | package | |
| libsdl2-image | no-dsa | bookworm | package | |
| libsdl2-image | postponed | bullseye | package | |
| libsdl3-image | fixed | 3.4.2+ds-1 | package | |
| libsdl3-image | no-dsa | trixie | package | |
| sdl-image1.2 | unfixed | package | ||
| sdl-image1.2 | no-dsa | trixie | package | |
| sdl-image1.2 | no-dsa | bookworm | package | |
| sdl-image1.2 | postponed | bullseye | package |
Примечания
https://github.com/libsdl-org/SDL_image/security/advisories/GHSA-gq8w-x74c-h6p7
https://github.com/libsdl-org/SDL_image/commit/996bf12888925932daace576e09c3053410896f8 (main)
https://github.com/libsdl-org/SDL_image/commit/a1a06276a51ca7e6e63908b200df8a278d8c5039 (SDL2)
https://github.com/libsdl-org/SDL_image/commit/678ac6a4c6021853485050926f45db08ba6aec48 (SDL-1.2)
EPSS
Связанные уязвимости
SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.
SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.
EPSS