SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.
https://security.gentoo.org/glsa/202107-55
https://lists.debian.org/debian-lts-announce/2023/02/msg00008.html
https://lists.debian.org/debian-lts-announce/2021/01/msg00024.html