CVE-2026-35444General(libsdl / sdl_image)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch libsdl sdl_image systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-125

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • sdl_image

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-06); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
sdl_image

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-06: 1Mentions · 2026-04-07: 1Mentions · 2026-06-21: 1Patch / Workaround · 2026-06-21: 1Technical Details · 2026-04-07: 104-0604-0706-21
Signal classification2 categories
General
266.7%
Patch
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-061
General1
2026-04-071
General1
2026-06-211
Patch1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🔒 Vulnerabilidade CVE-2026-35444 no mingw-SDL2_image afeta #Fedora 43. Guia completo com script de automação, verificações e mitigações alternativas. Proteja seu sistema agora . Saiba mais: -> http://tinyurl.com/4d4fw547 https://t.co/dPKxNbGo2E

    Post summary

    The post announces CVE‑2026‑35444 for Fedora 43 and offers a guide with an automation script and alternative mitigations to protect systems.

    1000058
    1.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-35444 Heap Out-of-Bounds Read in SDL_image XCF File Processing ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-35444 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet merely announces CVE-2026-35444 and links to a vulnerability detail page, offering no PoC, exploit, active use, patch, or debunking information.

    0000037
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-35444 SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are us… https://www.cve.org/CVERecord?id=CVE-2026-35444

    Post summary

    The snippet references CVE-2026-35444 with a link, mentioning a function in SDL_image’s XCF handling code, but provides no further technical detail or context.

    00000166
    57.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibsdlsdl_image---

Explore more