CVE-2019-13616: High severity libSDL Simple DirectMedia Layer vulnerability
Last updated 18 August 2025
Other sources
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDLblitN.c when called from SDLSoftBlit in video/SDLblit.c.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-13616?
CVE-2019-13616 is a vulnerability in SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 that allows a heap-based buffer over-read.
What is the severity of CVE-2019-13616?
The severity of CVE-2019-13616 is high, with a severity value of 8.1.
Which software versions are affected by CVE-2019-13616?
SDL versions through 1.2.15 and 2.x through 2.0.9 are affected by CVE-2019-13616.
How can I fix CVE-2019-13616?
To fix CVE-2019-13616, it is recommended to update SDL to version 1.2.12-5+ or higher.
Where can I find more information about CVE-2019-13616?
More information about CVE-2019-13616 can be found at the following references: [1](https://bugzilla.libsdl.org/show_bug.cgi?id=4538), [2](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00012.html), [3](http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00014.html).