{"id":"CVE-2026-35444","summary":"SDL_image has a heap buffer overflow READ via unchecked colormap index in XCF loader","details":"SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.","aliases":["GHSA-gq8w-x74c-h6p7"],"modified":"2026-09-30T08:42:35.020355220Z","published":"2026-04-06T21:44:05.986Z","related":["openSUSE-SU-2026:10493-1","openSUSE-SU-2026:10494-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35444.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-125"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35444.json"},{"type":"ADVISORY","url":"https://github.com/libsdl-org/SDL_image/security/advisories/GHSA-gq8w-x74c-h6p7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-35444"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/libsdl-org/sdl_image","events":[{"introduced":"0"},{"fixed":"996bf12888925932daace576e09c3053410896f8"}]}],"versions":["release-3.4.0","prerelease-3.3.4","prerelease-3.3.2","release-3.2.0","prerelease-3.1.1","preview-3.1.0","release-2.6.0","prerelease-2.5.3","prerelease-2.5.2","candidate-2.5.1","release-2.0.5","release-2.0.4","release-2.0.3","release-2.0.2","release-2.0.1","release-2.0.0","release-1.2.12","release-1.2.11","release-1.2.10","release-1.2.9","release-1.2.8","release-1.2.7","release-1.2.6","release-1.2.5"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-35444.json","vanir_signatures":[{"digest":{"function_hash":"332068281910124740413210049002281493220","length":4012},"id":"CVE-2026-35444-3d692704","signature_type":"Function","signature_version":"v1","source":"https://github.com/libsdl-org/sdl_image/commit/996bf12888925932daace576e09c3053410896f8","target":{"file":"src/IMG_xcf.c","function":"do_layer_surface"},"deprecated":false},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/libsdl-org/sdl_image/commit/996bf12888925932daace576e09c3053410896f8","target":{"file":"src/IMG_xcf.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["296831381542459481307686168142111125945","253545804121767353537492056836769757290","316150639664104863156441307503728595402","62950100641728955952428445177276794498","141616098339523467299231361343088260078","337411379400628825605691231819779173834","125289763410787881645662092964275932055","142522885684750495934434309629438646200","81901268143055052199640664750400961799","142915012377582019676798533915453107623","231707574912930585461341337133827182773","246328094036478702823228609912200752307","187989753621862183806499494913916000062","219789021993136860362376501698766523062","112502078769715721598420161516843044355","125289763410787881645662092964275932055","209085528716403728931980415980563168810","13960644311772602818792820555025105379","178400398808536327946025391679307413802","209832685458694728661718527754917887441","232543837663343178618560734129433773150","191186931675797132768633456219264710093","231784098114633940609944732083152142206","135600305986314827667237947165991171977","11669412658505797500117530952762462572","81901268143055052199640664750400961799","11774188730502055749817748258284427002","322564577428205770391111010416245097551","106860785284175124013505835876492002914","89090655529337713732883273032344036898","31814043146122625301154809548257575180","296245782909252292364734253346226008516","116929344730241579351985689133080335748","174827728290641076410238250545774953603"]},"id":"CVE-2026-35444-6fe2b514"}],"vanir_signatures_modified":"2026-09-30T08:42:35Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L"}]}