SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35444.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-35444.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "332068281910124740413210049002281493220",
"length": 4012
},
"id": "CVE-2026-35444-3d692704",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/libsdl-org/sdl_image/commit/996bf12888925932daace576e09c3053410896f8",
"target": {
"file": "src/IMG_xcf.c",
"function": "do_layer_surface"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"296831381542459481307686168142111125945",
"253545804121767353537492056836769757290",
"316150639664104863156441307503728595402",
"62950100641728955952428445177276794498",
"141616098339523467299231361343088260078",
"337411379400628825605691231819779173834",
"125289763410787881645662092964275932055",
"142522885684750495934434309629438646200",
"81901268143055052199640664750400961799",
"142915012377582019676798533915453107623",
"231707574912930585461341337133827182773",
"246328094036478702823228609912200752307",
"187989753621862183806499494913916000062",
"219789021993136860362376501698766523062",
"112502078769715721598420161516843044355",
"125289763410787881645662092964275932055",
"209085528716403728931980415980563168810",
"13960644311772602818792820555025105379",
"178400398808536327946025391679307413802",
"209832685458694728661718527754917887441",
"232543837663343178618560734129433773150",
"191186931675797132768633456219264710093",
"231784098114633940609944732083152142206",
"135600305986314827667237947165991171977",
"11669412658505797500117530952762462572",
"81901268143055052199640664750400961799",
"11774188730502055749817748258284427002",
"322564577428205770391111010416245097551",
"106860785284175124013505835876492002914",
"89090655529337713732883273032344036898",
"31814043146122625301154809548257575180",
"296245782909252292364734253346226008516",
"116929344730241579351985689133080335748",
"174827728290641076410238250545774953603"
],
"threshold": 0.9
},
"id": "CVE-2026-35444-6fe2b514",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/libsdl-org/sdl_image/commit/996bf12888925932daace576e09c3053410896f8",
"target": {
"file": "src/IMG_xcf.c"
}
}
]
"2026-09-30T08:42:35Z"