← Vulnerability feed

Vulnerability record · CVE-2019-12222 · published 20 May 2019

CVE-2019-12222: Libsdl simple directmedia layer out-of-bounds read vulnerability

Libsdl · Simple Directmedia Layer

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at video/SDL_pixels.c.

6.5 CVSS 3.0 Medium EPSS 1.9% · top 20.8% CWE-125 · Out-of-bounds read
6.5CVSS 3.0 base score, v2 4.3
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9. There is an out-of-bounds read in the function SDL_InvalidateMap at video/SDL_pixels.c.

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-12222 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-14906Libsdl simple directmedia layer out-of-bounds read vulnerabilityA flaw was found with the RHSA-2019:3950 erratum, where it did not fix the CVE-2019-13616 SDL vulnerability. This issue only affects Red Hat SDL pack…EPSS 1.8%8.8CVE-2021-33657Libsdl simple directmedia layer out-of-bounds write vulnerabilityThere is a heap overflow problem in video/SDL_pixels.c in SDL (Simple DirectMedia Layer) 2.x to 2.0.18 versions. By crafting a malicious .BMP file, a…EPSS 2.1%8.8CVE-2019-12219Libsdl sdl2 image double free vulnerabilityAn issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2_image 2.0.4. There…EPSS 2.0%8.8CVE-2019-7637Libsdl simple directmedia layer out-of-bounds write vulnerabilitySDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer overflow in SDL_FillRect in video/SDL_surface.c.EPSS 3.1%8.8CVE-2019-7638Libsdl simple directmedia layer out-of-bounds read vulnerabilitySDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.EPSS 2.9%8.8CVE-2019-7572Libsdl simple directmedia layer out-of-bounds read vulnerabilitySDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.EPSS 2.8%8.8CVE-2019-7573Libsdl simple directmedia layer out-of-bounds read vulnerabilitySDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (inside the…EPSS 3.0%8.8CVE-2019-7574Libsdl simple directmedia layer out-of-bounds read vulnerabilitySDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.EPSS 2.8%

Source: NIST National Vulnerability Database (record CVE-2019-12222), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.