A potential memory leak issue was discovered in SDL2 in GLES_CreateTexture() function in SDL_render_gles.c. The vulnerability allows an attacker to cause a denial of service attack. The vulnerability affects SDL2 v2.0.4 and above. SDL-1.x are not affected.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade SDL2Upgrade SDL2-debuginfoUpgrade SDL2-develUpgrade SDL2-static | Jul 27, 2023 | Jan 12, 2023 |
| Debian | — | Upgrade libsdl2 | Feb 10, 2023 | Jan 12, 2023 |
| Gentoo Linux | — | Upgrade media-libs/libsdl2. | May 4, 2023 | Jan 12, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 12, 2023 |
| Suse | — | Upgrade libsdl2-2_0-0Upgrade libsdl2-devel-32bitUpgrade libsdl2-develUpgrade libsdl2-2_0-0-32bit | Jan 12, 2023 | Jan 11, 2023 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Jan 12, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub