Debian Patches

Status for libsdl2-image/2.8.8+dfsg-1+deb13u1

Patch Description Author Forwarded Bugs Origin Last update
Fixed-out-of-bounds-read-in-XCF-image-loader-thanks-Sebas.patch Fixed out of bounds read in XCF image loader (thanks @Sebasteuo!)
(cherry picked from commit f55d589ba5de11c724afcdcae80b56bf26d91d15)
(cherry picked from commit a1a06276a51ca7e6e63908b200df8a278d8c5039)
Sam Lantinga <slouken@libsdl.org> yes debian upstream upstream, 2.8.10, commit:fa9ffb8cced56aba2a2ab27d7c4388278e6b70c0 2026-04-02
xpm-Remove-QUICK_COLORHASH-replace-it-with-inline-code-th.patch xpm: Remove QUICK_COLORHASH, replace it with inline code that checks for NULL.

Closes #721.

(cherry picked from commit bc17bc7c6a2767e342ebb6d3fd37c8e323c8dd70)
"Ryan C. Gordon" <icculus@icculus.org> yes upstream upstream, 2.8.12, commit:5df1ec7d9dda53c02f251971e2169690c50211d8 2026-04-06
Fix-heap-buffer-overflow-WRITE-in-LBM-palette-CWE-122.patch Fix heap-buffer-overflow WRITE in LBM palette (CWE-122)
When nbplanes > 8 without HAM flag, nbrcolorsfinal exceeds 256,
causing writes past the palette buffer. Reject nbplanes > 8 for
paletted images.

(cherry picked from commit 2fe0746733c9f280d2c344bce231dd70fdf3bdb8)
Jorge Barredo Ferreira <jorgebarredo14@gmail.com> no https://github.com/libsdl-org/SDL_image/pull/717 2026-04-06
xcf-Permit-empty-strings-in-read_string.patch xcf: Permit empty strings in read_string().
Reference Issue #716.

(cherry picked from commit 1da905ae95748edbf063102574be5f25ff42ae39)
"Ryan C. Gordon" <icculus@icculus.org> yes upstream upstream, 2.8.12, commit:2d2928376e1e044fd9e501d25e6e39e71b8fb85c 2026-04-06
Fix-heap-buffer-overflow-READ-in-XCF-do_layer_surface-CWE.patch Fix heap-buffer-overflow READ in XCF do_layer_surface (CWE-122)
Add bounds check for tile buffer access in do_layer_surface.

(cherry picked from commit 5b0d414cae99b2e162a1e46ecba4fcd7ac8c5d85)
Jorge Barredo Ferreira <jorgebarredo14@gmail.com> no https://github.com/libsdl-org/SDL_image/pull/719 2026-04-06
xcf-Added-an-SDL_SetError-when-rejecting-out-of-bounds-ti.patch xcf: Added an SDL_SetError when rejecting out-of-bounds tile data.
(cherry picked from commit 1aedddcbd205c4e1ea0f99fdb2c785acc8e2489b)

[This fixes incorrect error reporting by #719 -smcv]
"Ryan C. Gordon" <icculus@icculus.org> no upstream, 2.8.12, commit:cde1749f5223d7b99750fb79e7822fe11797a2a8 2026-04-06
xcf-Fix-heap-buffer-overflow-READ-in-XCF-RLE-decoder-CWE-.patch xcf: Fix heap-buffer-overflow READ in XCF RLE decoder (CWE-122)
Add destination pointer bounds check in load_xcf_tile_rle.

This fix backported to SDL2 from 6c804082117c95c24b3d3af886319e8c21fcd8e0.

(cherry picked from commit 3ce6cb6f968427cd1041f9dc7b0bb6024fd4c782)
"Ryan C. Gordon" <icculus@icculus.org> no backport, https://github.com/libsdl-org/SDL_image/pull/720 2026-04-06
xcf-fix-null-pointer-dereference-when-read_xcf_hierarchy-.patch xcf: fix null pointer dereference when read_xcf_hierarchy() fails
read_xcf_hierarchy() can return NULL when SDL_calloc() fails or when
SDL_ReadU32BE() fails to read the width/height/bpp fields. The return
value was not checked before dereferencing hierarchy->bpp at line 755
in do_layer_surface(), leading to a null pointer dereference.

Add a NULL check immediately after the call to return early with an
error in that case.

CWE-476 (NULL Pointer Dereference)
Found by: NORAI fuzzer (libFuzzer + ASan/UBSan)

(cherry picked from commit 336fb104494815984250c40f8ee6bd1325b7ba1e)
(cherry picked from commit be7fee9064ed15d88e0bc573c018045daacfd01a)
Jorge Barredo Ferreira <jorgebarredo14@gmail.com> no https://github.com/libsdl-org/SDL_image/pull/722 2026-04-07
tga-reject-images-with-zero-width-or-height.patch tga: reject images with zero width or height
When SDL_CreateSurface() is called with w=0 or h=0 it may return a
non-NULL surface but with a NULL pixels pointer (zero-size allocation).
Subsequent code at IMG_LoadTGA_IO accesses img->pixels unconditionally,
resulting in undefined behavior: UBSan reports "applying zero offset to
null pointer" for the expression (Uint8*)img->pixels + (h-1)*img->pitch
when pitch is 0.

Reject zero-dimension images early before creating the surface.

CWE-476 (NULL Pointer Dereference)
Found by: NORAI fuzzer (libFuzzer + UBSan)

(cherry picked from commit 4ba58feebaf87ad80b8ab3971ea8f82132884c54)
(cherry picked from commit 9f1318e7c112493fcd224eafe8809d4001d1bb33)
Jorge Barredo Ferreira <jorgebarredo14@gmail.com> no upstream, 2.8.12, commit:67c8f531ad09ddc0e6d4c7b1468c863235711ed4 2026-04-23
Fixed-out-of-bound-read-in-GIF-decoder.patch Fixed out of bound read in GIF decoder
Fixes https://github.com/libsdl-org/SDL_image/issues/724

(cherry picked from commit e2b258927d11438cbf4ee55a5c4ff059a6e32d08)
(cherry picked from commit 2c02f371f55a2f74a291639d95761066ac2afff0)
Sam Lantinga <slouken@libsdl.org> yes upstream upstream, 2.8.12, commit:38fdd07d43a01b604fffb7453bff3ae2e9fd339a 2026-04-29
IMG_xcf.c-read_string-add-back-the-positive-string-size-c.patch IMG_xcf.c (read_string): add back the positive string size check
[Otherwise a claimed size >= 2**31 bytes could lead to underflow. -smcv]

(cherry picked from commit cdbe3bf771606a3502c1c5994812bfc48d4814a0)
Ozkan Sezer <sezeroz@gmail.com> no upstream, 2.8.12, commit:d23a437d9b620cfca437ffa5aa332799435973bd 2026-05-13

All known versions for source package 'libsdl2-image'

Links