CVE-2026-32836 MEDIUM

CVE-2026-32836: mackron / dr_libs dr_flac.h Excessive Memory Allocation in PICTURE Metadata Parsing

Vendor Mackron
Product dr_libs dr_flac.h
Weakness CWE-789
Published March 17, 2026
Last update April 29, 2026

CVSS base score

6.9/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.

Key dates

02Disclosure timeline

March 17, 2026 CVE published
April 29, 2026 Record updated