CVE-2019-7636: High severity libSDL Simple DirectMedia Layer vulnerability
Published Feb 8, 2019
·Updated
Last updated 25 August 2025
Other sources
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in SDLGetRGB in video/SDLpixels.c.
— Launchpad
Affected Software
14 affected componentsFixes available
libSDL Simple DirectMedia Layer<=1.2.15
libSDL Simple DirectMedia Layer>=2.0.0<=2.0.9
openSUSE Leap=15.0
openSUSE Leap=42.3
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Fedoraproject Fedora=31
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=18.04
Canonical Ubuntu Linux=19.04
debian/libsdl1.2
1.2.15+dfsg2-61.2.15+dfsg2-8
debian/libsdl2
2.0.14+dfsg2-3+deb11u12.0.14+dfsg2-3+deb11u22.26.5+dfsg-12.32.4+dfsg-12.32.10+dfsg-6
Remediation
Patch Available
Patch Available
Event History
Feb 8, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·11:08 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·11:08 PM
Description
Data Sourced
via Debian·11:08 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-7636?
CVE-2019-7636 is a vulnerability in SDL (Simple DirectMedia Layer) through version 1.2.15 and 2.x through version 2.0.9.
2
What is the severity of CVE-2019-7636?
The severity of CVE-2019-7636 is high with a CVSS score of 8.1.
3
How does CVE-2019-7636 impact SDL?
CVE-2019-7636 is a heap-based buffer over-read vulnerability in SDL_GetRGB function in video/SDL_pixels.c.
4
Which software versions are affected by CVE-2019-7636?
SDL versions 1.2.15 and 2.x through 2.0.9 are affected by CVE-2019-7636.
5
How can I fix CVE-2019-7636?
To fix CVE-2019-7636, update your SDL software to version 1.2.15+dfsg2-0.1ubuntu0.1 or 2.0.9+dfsg1-1ubuntu1.19.04.1 or later.