CVE-2019-7572: High severity libSDL Simple DirectMedia Layer vulnerability
Last updated 18 August 2025
Other sources
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMAADPCMnibble in audio/SDLwave.c.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-7572?
CVE-2019-7572 is a vulnerability in SDL (Simple DirectMedia Layer) versions 1.2.15 through 2.0.9 that allows for a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
How severe is CVE-2019-7572?
CVE-2019-7572 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2019-7572?
SDL (Simple DirectMedia Layer) versions 1.2.15 through 1.2.15+dfsg2-8 and 2.x through 2.0.9+dfsg1-1 are affected by CVE-2019-7572.
How can I fix CVE-2019-7572?
To fix CVE-2019-7572, ensure that you are using SDL version 1.2.15+dfsg2-6~deb10u1, 1.2.15+dfsg2-6, 1.2.15+dfsg2-8, 2.0.9+dfsg1-1+deb10u1, 2.0.14+dfsg2-3+deb11u1, 2.26.5+dfsg-1, or 2.28.4+dfsg-1, depending on the version you are using.
Where can I find more information about CVE-2019-7572?
More information about CVE-2019-7572 can be found on the following references: - [Bugzilla](https://bugzilla.libsdl.org/show_bug.cgi?id=4495) - [SDL Discourse](https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720) - [Debian LTS Announce](https://lists.debian.org/debian-lts-announce/2019/03/msg00015.html)