CVE-2019-7573: High severity libSDL Simple DirectMedia Layer vulnerability
Published Feb 7, 2019
·Updated
Last updated 18 August 2025
Other sources
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMSADPCM in audio/SDLwave.c (inside the wNumCoef loop).
— Launchpad
Affected Software
13 affected componentsFixes available
libSDL Simple DirectMedia Layer<=1.2.15
libSDL Simple DirectMedia Layer>=2.0.0<=2.0.9
Debian Debian Linux=8.0
Debian Debian Linux=9.0
openSUSE Leap=15.0
openSUSE Leap=42.3
Fedoraproject Fedora=31
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
debian/libsdl1.2
1.2.15+dfsg2-61.2.15+dfsg2-8
debian/libsdl2
2.0.14+dfsg2-3+deb11u12.0.14+dfsg2-3+deb11u22.26.5+dfsg-12.32.4+dfsg-12.32.10+dfsg-6
Remediation
Patch Available
Patch Available
Event History
Feb 7, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·11:10 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·11:11 PM
DescriptionAffected Software
Data Sourced
via Launchpad·11:11 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-7573.
2
What is the severity of CVE-2019-7573?
The severity of CVE-2019-7573 is high.
3
How does CVE-2019-7573 affect SDL (Simple DirectMedia Layer)?
CVE-2019-7573 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c of SDL (Simple DirectMedia Layer) through versions 1.2.15 and 2.x through 2.0.9.
4
Which software versions are affected by CVE-2019-7573?
SDL (Simple DirectMedia Layer) versions 1.2.15 and 2.x through 2.0.9 are affected by CVE-2019-7573.
5
How can I fix CVE-2019-7573?
To fix CVE-2019-7573, update SDL (Simple DirectMedia Layer) to a version that includes the necessary patches.