CVE-2026-35444

Source
https://cve.org/CVERecord?id=CVE-2026-35444
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-35444.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-35444
Aliases
  • GHSA-gq8w-x74c-h6p7
Downstream
DEBIAN (1)
openSUSE (2)
UBUNTU (1)
Related
Published
2026-04-06T21:44:05Z
Modified
2026-09-30T08:42:35Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L CVSS Calculator
Summary
SDL_image has a heap buffer overflow READ via unchecked colormap index in XCF loader
Details

SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35444.json"
}
References

Affected packages

Git / github.com/libsdl-org/sdl_image

Affected ranges

Type
GIT
Repo
https://github.com/libsdl-org/sdl_image
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

candidate-2.*
candidate-2.5.1
prerelease-2.*
prerelease-2.5.2
prerelease-2.5.3
prerelease-3.*
prerelease-3.1.1
prerelease-3.3.2
prerelease-3.3.4
preview-3.*
preview-3.1.0
release-1.*
release-1.2.10
release-1.2.11
release-1.2.12
release-1.2.5
release-1.2.6
release-1.2.7
release-1.2.8
release-1.2.9
release-2.*
release-2.0.0
release-2.0.1
release-2.0.2
release-2.0.3
release-2.0.4
release-2.0.5
release-2.6.0
release-3.*
release-3.2.0
release-3.4.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-35444.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "332068281910124740413210049002281493220",
            "length": 4012
        },
        "id": "CVE-2026-35444-3d692704",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/libsdl-org/sdl_image/commit/996bf12888925932daace576e09c3053410896f8",
        "target": {
            "file": "src/IMG_xcf.c",
            "function": "do_layer_surface"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "296831381542459481307686168142111125945",
                "253545804121767353537492056836769757290",
                "316150639664104863156441307503728595402",
                "62950100641728955952428445177276794498",
                "141616098339523467299231361343088260078",
                "337411379400628825605691231819779173834",
                "125289763410787881645662092964275932055",
                "142522885684750495934434309629438646200",
                "81901268143055052199640664750400961799",
                "142915012377582019676798533915453107623",
                "231707574912930585461341337133827182773",
                "246328094036478702823228609912200752307",
                "187989753621862183806499494913916000062",
                "219789021993136860362376501698766523062",
                "112502078769715721598420161516843044355",
                "125289763410787881645662092964275932055",
                "209085528716403728931980415980563168810",
                "13960644311772602818792820555025105379",
                "178400398808536327946025391679307413802",
                "209832685458694728661718527754917887441",
                "232543837663343178618560734129433773150",
                "191186931675797132768633456219264710093",
                "231784098114633940609944732083152142206",
                "135600305986314827667237947165991171977",
                "11669412658505797500117530952762462572",
                "81901268143055052199640664750400961799",
                "11774188730502055749817748258284427002",
                "322564577428205770391111010416245097551",
                "106860785284175124013505835876492002914",
                "89090655529337713732883273032344036898",
                "31814043146122625301154809548257575180",
                "296245782909252292364734253346226008516",
                "116929344730241579351985689133080335748",
                "174827728290641076410238250545774953603"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-35444-6fe2b514",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/libsdl-org/sdl_image/commit/996bf12888925932daace576e09c3053410896f8",
        "target": {
            "file": "src/IMG_xcf.c"
        }
    }
]
vanir_signatures_modified
"2026-09-30T08:42:35Z"