CVE-2026-32836
Published: Mar 17, 2026
Modified: Apr 29, 2026
CVSS v3.1
6.2
Description
dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.
| Vendor | Product | Versions |
|---|---|---|
mackron | dr_libs dr_flac.h | affected 0 - <= 0.13.3unaffected fefced4a64adfb1a68a2d31d882366e56096dee8unaffected 4f5a4cd3b57564d969443c580c75857e039f100aunaffected 663239a3d0460c33bd5b6e5166edcb404e3df676 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now