CVE Database
/

CVE-2026-32836

Back to search

CVE-2026-32836

Published: Mar 17, 2026

Modified: Apr 29, 2026

PUBLISHED

CVSS v3.1

6.2

MEDIUM

Description

dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.

VendorProductVersions

mackron

dr_libs dr_flac.h

affected
0 - <= 0.13.3
unaffected
fefced4a64adfb1a68a2d31d882366e56096dee8
unaffected
4f5a4cd3b57564d969443c580c75857e039f100a
unaffected
663239a3d0460c33bd5b6e5166edcb404e3df676

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

None

Integrity

None

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now
CVE-2026-32836 | MEDIUM (6.2) - Security Vulnerability | QwikSec