#1140481 libretro-snes9x: CVE-2026-39199

Package:
src:libretro-snes9x
Source:
src:libretro-snes9x
Submitter:
Salvatore Bonaccorso
Date:
2026-06-27 11:51:03 UTC
Severity:
normal
Tags:
#1140481#5
Date:
2026-06-21 11:49:22 UTC
From:
To:
Hi,

The following vulnerability was published for libretro-snes9x.

CVE-2026-39199[0]:
| snes9x 1.63 allows an out-of-bounds write and denial of service via
| a crafted .ups file.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-39199
https://www.cve.org/CVERecord?id=CVE-2026-39199
[1] https://github.com/snes9xgit/snes9x/issues/1035
[2] https://karansaini.com/snes9x-oob-write/
[3] https://github.com/snes9xgit/snes9x/commit/96b366100172723f6314c40e237b370f4f7b59f4

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1140481#12
Date:
2026-06-27 11:48:40 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
libretro-snes9x, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140481@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jonathan McDowell <noodles@earth.li> (supplier of updated libretro-snes9x package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 27 Jun 2026 12:35:07 +0100
Source: libretro-snes9x
Architecture: source
Version: 1.63+dfsg-2
Distribution: unstable
Urgency: high
Maintainer: Debian Games Team <pkg-games-devel@lists.alioth.debian.org>
Changed-By: Jonathan McDowell <noodles@earth.li>
Closes: 1140481
Changes:
 libretro-snes9x (1.63+dfsg-2) unstable; urgency=high
 .
    * Fix out of bounds .ups access (CVE-2026-39199) (Closes: #1140481)
Checksums-Sha1:
 20af547260b199f451bcdb9290919f20637569f0 1436 libretro-snes9x_1.63+dfsg-2.dsc
 2b80e143547243ba75afab2ea0a0744787a5d1bb 6332 libretro-snes9x_1.63+dfsg-2.debian.tar.xz
 31f19fab02e33d5c29811b001e23625c7c0a3632 5704 libretro-snes9x_1.63+dfsg-2_amd64.buildinfo
Checksums-Sha256:
 ca9d5193cbd4343386551ea3be358a370545706b63efcd2603d694f7ee56b1e3 1436 libretro-snes9x_1.63+dfsg-2.dsc
 b6d6cc237a4125b09236908f58290d3084e87a8111df156c46ca1e2f73a27947 6332 libretro-snes9x_1.63+dfsg-2.debian.tar.xz
 7214cb0b1a9b9c4a248cd645fe06e9cc493820408ada7068aea02b6a8d81dd32 5704 libretro-snes9x_1.63+dfsg-2_amd64.buildinfo
Files:
 2e7e916ff19ca13a39a5843d32723feb 1436 non-free/games optional libretro-snes9x_1.63+dfsg-2.dsc
 714800dee523422cbf4798d0c2b4e7d5 6332 non-free/games optional libretro-snes9x_1.63+dfsg-2.debian.tar.xz
 922d553570dc24625295dc169aabb4a9 5704 non-free/games optional libretro-snes9x_1.63+dfsg-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQSAYP1ALvrBQa1odmMPwJuF4mk8PAUCaj+1/AAKCRAPwJuF4mk8
PO7QAP9QgsdYembqs+Q6FEXhsHHy+WgOErE8h686jL9XgPFYggD/aZSAuZM4STt5
eCnNDMwW3ULn4ouux5Pumu5fhQcmkwc=
=h6TR
-----END PGP SIGNATURE-----