Medium severity6.2NVD Advisory· Published Mar 17, 2026· Updated Apr 27, 2026
CVE-2026-32836
CVE-2026-32836
Description
dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
5- github.com/mackron/dr_libs/issues/298nvdExploitIssue TrackingMitigationVendor Advisory
- www.vulncheck.com/advisories/mackron-dr-libs-excessive-memory-allocation-in-picture-metadata-parsingnvdThird Party Advisory
- github.com/mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100anvd
- github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676nvd
- github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8nvd
News mentions
0No linked articles in our index yet.