Debian Package Tracker
Register | Log in
Subscribe

libsdl3-image

Choose email to subscribe with

general
  • source: libsdl3-image (main)
  • version: 3.4.2+ds-1
  • maintainer: Debian SDL packages maintainers (archive) (DMD)
  • uploaders: Simon McVittie [DMD] – Manuel A. Fernandez Montecelo [DMD] – Felix Geyer [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • stable: 3.2.4+ds-1
  • testing: 3.4.0+ds-1
  • unstable: 3.4.2+ds-1
versioned links
  • 3.2.4+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.4.0+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.4.2+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libsdl3-image-dev
  • libsdl3-image-doc
  • libsdl3-image-tests
  • libsdl3-image0
action needed
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-35444: SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.
Created: 2026-04-07 Last update: 2026-04-14 09:00
1 low-priority security issue in trixie low

There is 1 open security issue in trixie.

1 issue left for the package maintainer to handle:
  • CVE-2026-35444: (needs triaging) SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap and out-of-range pixel indices causes heap out-of-bounds reads of up to 762 bytes past the colormap allocation. Both IMAGE_INDEXED code paths are affected (bpp=1 and bpp=2). The leaked heap bytes are written into the output surface pixel data, making them potentially observable in the rendered image. This vulnerability is fixed with commit 996bf12888925932daace576e09c3053410896f8.

You can find information about how to handle this issue in the security team's documentation.

Created: 2026-04-07 Last update: 2026-04-14 09:00
debian/patches: 5 patches to forward upstream low

Among the 6 debian patches available in version 3.4.2+ds-1 of the package, we noticed the following issues:

  • 5 patches where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2026-04-11 Last update: 2026-04-11 08:00
testing migrations
  • excuses:
    • Migration status for libsdl3-image (3.4.0+ds-1 to 3.4.2+ds-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Too young, only 4 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/libs/libsdl3-image.html
    • ∙ ∙ Autopkgtest for libsdl3-image/3.4.2+ds-1: amd64: No tests, superficial or marked flaky ♻, arm64: No tests, superficial or marked flaky ♻, i386: No tests, superficial or marked flaky ♻, ppc64el: No tests, superficial or marked flaky ♻, riscv64: No tests, superficial or marked flaky ♻, s390x: No tests, superficial or marked flaky ♻
    • ∙ ∙ Reproduced on amd64
    • ∙ ∙ Reproduced on arm64
    • ∙ ∙ Reproduced on armhf
    • ∙ ∙ Reproducibility check waiting for results on i386
    • ∙ ∙ Reproducibility check waiting for results on ppc64el
    • Not considered
news
[rss feed]
  • [2026-04-10] Accepted libsdl3-image 3.4.2+ds-1 (source) into unstable (Simon McVittie)
  • [2026-01-27] libsdl3-image 3.4.0+ds-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-22] Accepted libsdl3-image 3.4.0+ds-1 (source) into unstable (Simon McVittie)
  • [2026-01-20] Accepted libsdl3-image 3.3.4+ds-2 (source) into experimental (Simon McVittie)
  • [2026-01-19] Accepted libsdl3-image 3.3.4+ds-1 (source) into experimental (Simon McVittie)
  • [2026-01-08] libsdl3-image 3.2.6+ds-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-02] Accepted libsdl3-image 3.2.6+ds-1 (source) into unstable (Simon McVittie)
  • [2025-03-09] libsdl3-image 3.2.4+ds-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-04] Accepted libsdl3-image 3.2.4+ds-1 (source) into unstable (Simon McVittie)
  • [2025-03-03] Accepted libsdl3-image 3.2.2+ds-2 (source) into unstable (Simon McVittie)
  • [2025-03-03] Accepted libsdl3-image 3.2.2+ds-1 (source) into unstable (Simon McVittie)
  • [2025-02-10] libsdl3-image 3.2.0+ds-2 MIGRATED to testing (Debian testing watch)
  • [2025-02-04] Accepted libsdl3-image 3.2.0+ds-2 (source) into unstable (Simon McVittie)
  • [2025-02-03] Accepted libsdl3-image 3.2.0+ds-1 (source) into unstable (Simon McVittie)
  • [2025-01-24] Accepted libsdl3-image 3.1.1+ds-1 (source) into unstable (Simon McVittie)
  • [2025-01-19] Accepted libsdl3-image 3.1.0+ds-2 (source) into unstable (Simon McVittie)
  • [2025-01-08] Accepted libsdl3-image 3.1.0+ds-1 (source) into unstable (Simon McVittie)
  • [2024-11-04] Accepted libsdl3-image 3~git20241102~b1c8ec7+ds-1 (source) into experimental (Simon McVittie)
  • [2024-10-04] Accepted libsdl3-image 3~git20240925~6f45843+ds-1 (source) into experimental (Simon McVittie)
  • [2024-09-17] Accepted libsdl3-image 3~git20240915~6f04db8+ds-1 (source) into experimental (Simon McVittie)
  • [2024-09-03] Accepted libsdl3-image 3~git20240828~0901204+ds-1 (source) into experimental (Simon McVittie)
  • [2024-07-30] Accepted libsdl3-image 3~git20240726~2a27018+ds-1 (source) into experimental (Simon McVittie)
  • [2024-06-20] Accepted libsdl3-image 3~git20240508~ff62eb6+ds-1 (source) into experimental (Simon McVittie)
  • [2024-03-25] Accepted libsdl3-image 3~git20240319~18b2816+ds-1 (source) into experimental (Simon McVittie)
  • [2024-01-30] Accepted libsdl3-image 3~git20240129~750f1c1+ds-1 (source) into experimental (Simon McVittie)
  • [2024-01-22] Accepted libsdl3-image 3~git20240118~c47680c+ds-1 (source) into experimental (Simon McVittie)
  • [2024-01-15] Accepted libsdl3-image 3~git20240115~6d91bf7+ds-1 (source) into experimental (Simon McVittie)
  • [2024-01-03] Accepted libsdl3-image 3~git20240101~1a35931+ds-1 (source) into experimental (Simon McVittie)
  • [2023-12-07] Accepted libsdl3-image 3~git20231130~25a57e2+ds-1 (source) into experimental (Simon McVittie)
  • [2023-10-02] Accepted libsdl3-image 3~git20230930~e1e15ae+ds-1 (source) into experimental (Simon McVittie)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 3.4.0+ds-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing