Critical Information Disclosure in Fedora 43 and 44 SDL2_image CVE-2026-35444

Critical Information Disclosure in Fedora 43 and 44 SDL2_image CVE-2026-35444

First seen 21 Jun 2026, 02:19 UTC Linuxsecurity 80% similarity 57.9

Article Content

Browse articles
ThreatCluster

Fedora has released updates for the mingw-SDL2_image package due to a critical information disclosure vulnerability (CVE-2026-35444) affecting crafted XCF files. The vulnerability was published on April 6, 2026, and can lead to unauthorized information exposure. Users of Fedora 43 and 44 are encouraged to update their systems to mitigate this risk. The updates can be installed using the 'dnf' package manager. The vulnerability affects all Fedora users utilizing the SDL_image library. No active exploitation has been reported yet, but the potential for data exposure is significant. Users are advised to apply the patches promptly to secure their systems.

Key Points: • CVE-2026-35444 allows information disclosure via crafted XCF files in SDL_image. • Fedora 43 and 44 users are at risk and should update their systems immediately. • Updates are available through the 'dnf' package manager for affected Fedora versions.

ThreatCluster AI How this analysis works

Timeline

2026-04-06
CVE-2026-35444 published
A critical information disclosure vulnerability in SDL_image was published, affecting crafted XCF files.
Linuxsecurity
2026-05-15
Fedora 43 update released
An update to version 2.8.12-1 was released to address CVE-2026-35444 for Fedora 43 users.
Linuxsecurity
2026-06-21
Fedora 44 update released
An update for Fedora 44 was also released to fix the same vulnerability, ensuring user protection.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story