CVE-2025-14369 Details
Description
dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
A denial-of-service vulnerability has been identified in dr_flac, an audio decoder within the dr_libs toolset. The issue arises from an integer overflow caused by the decoder trusting the totalPCMFrameCount field from FLAC metadata without proper validation before calculating the buffer size. This flaw allows an attacker to craft a malicious FLAC file that, when processed by dr_flac, can lead to excessive memory allocation and cause programs using this tool to crash.
The vulnerability has been patched in commit b2197b2. Users should update to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 20, 2026CISA-ADP
Assessed Jan 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.kb.cert.org/vuls/id/924114 | CVE | AdvisoryRemedy |
| https://github.com/mackron/dr_libs/commit/b2197b2eb7bb609df76315bebf44db4ec2a1aed0 | [email protected] | Source CodeVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| mackron dr_flac | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 20, 2026 | CVE Modified | CISA-ADP |
| Jan 20, 2026 | CVE Modified | CVE |
| Jan 20, 2026 | New CVE Received | [email protected] |
Volerion