CVE-2019-7574: High severity libSDL Simple DirectMedia Layer vulnerability
Last updated 18 August 2025
Other sources
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMAADPCMdecode in audio/SDLwave.c.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-7574.
What is the severity of CVE-2019-7574?
The severity of CVE-2019-7574 is high with a severity value of 8.8.
Which software versions are affected by CVE-2019-7574?
SDL (Simple DirectMedia Layer) versions 1.2.15 through 1.2.15 and 2.x through 2.0.9 are affected by CVE-2019-7574.
How can I fix the vulnerability in SDL?
To fix the vulnerability in SDL, update to the patched versions: 1.2.15+dfsg2-6~deb10u1, 1.2.15+dfsg2-6, 1.2.15+dfsg2-8, 2.0.9+dfsg1-1+deb10u1, 2.0.14+dfsg2-3+deb11u1, 2.26.5+dfsg-1, or 2.28.4+dfsg-1.
Where can I find more information about CVE-2019-7574?
You can find more information about CVE-2019-7574 at the following references: [1](https://bugzilla.libsdl.org/show_bug.cgi?id=4496), [2](https://discourse.libsdl.org/t/vulnerabilities-found-in-libsdl-1-2-15/25720), [3](https://lists.debian.org/debian-lts-announce/2019/03/msg00015.html).