CVE-2026-32836 Details
Description
dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.
A vulnerability allowing uncontrolled memory allocation has been identified in dr_libs versions through 0.13.3. This issue arises in the function drflac__read_and_decode_metadata(), where the PICTURE metadata blocks are processed. Attackers can exploit this vulnerability by crafting FLAC streams that include manipulated mimeLength and descriptionLength fields, leading to excessive memory allocation. This exploitation causes a denial-of-service condition by exhausting available memory, particularly when FLAC streams are handled with metadata callbacks.
Users are advised to update to dr_libs version 0.13.4 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-789 | Memory Allocation with Excessive Size Value | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| mackron dr libs | <= 0.13.3 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | CVE Modified | [email protected] |
| Mar 20, 2026 | CVE Modified | [email protected] |
| Mar 19, 2026 | Initial Analysis | [email protected] |
| Mar 17, 2026 | New CVE Received | [email protected] |