CVE-2026-32836

dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:*

History

27 Apr 2026, 16:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 6.2
References
  • () https://github.com/mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100a -
  • () https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676 -
  • () https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8 -
Summary (en) dr_libs dr_flac.h version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks. (en) dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.

20 Mar 2026, 18:16

Type Values Removed Values Added
Summary (en) dr_libs version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks. (en) dr_libs dr_flac.h version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.

19 Mar 2026, 19:28

Type Values Removed Values Added
References () https://github.com/mackron/dr_libs/issues/298 - () https://github.com/mackron/dr_libs/issues/298 - Exploit, Issue Tracking, Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/mackron-dr-libs-excessive-memory-allocation-in-picture-metadata-parsing - () https://www.vulncheck.com/advisories/mackron-dr-libs-excessive-memory-allocation-in-picture-metadata-parsing - Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:*
First Time Mackron dr Libs
Mackron

18 Mar 2026, 14:52

Type Values Removed Values Added
Summary
  • (es) La versión 0.13.3 y anteriores de dr_libs contienen una vulnerabilidad de asignación de memoria incontrolada en drflac__read_and_decode_metadata() que permite a los atacantes activar una asignación de memoria excesiva al proporcionar bloques de metadatos PICTURE manipulados. Los atacantes pueden explotar los campos mimeLength y descriptionLength controlados por el atacante para causar una denegación de servicio a través del agotamiento de la memoria al procesar flujos FLAC con devoluciones de llamada de metadatos.

17 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-17 20:16

Updated : 2026-04-27 16:16


NVD link : CVE-2026-32836

Mitre link : CVE-2026-32836

CVE.ORG link : CVE-2026-32836


JSON object : View

Products Affected

mackron

  • dr_libs
CWE
CWE-789

Memory Allocation with Excessive Size Value