Integer Overflow Vulnerability in dr_flac Audio Decoder by dr_libs
CVE-2025-14369

5.5MEDIUM

Key Information:

Vendor

Mackron

Status
Vendor
CVE Published:
20 January 2026

What is CVE-2025-14369?

The dr_flac audio decoder within the dr_libs toolset has an integer overflow vulnerability. This flaw arises from the improper validation of the totalPCMFrameCount field derived from FLAC metadata prior to computing the buffer size. An attacker could exploit this vulnerability by delivering a specially crafted FLAC file, potentially leading to a Denial of Service (DoS) when processed by applications utilizing dr_flac.

Affected Version(s)

dr_flac 0 <= 0.13.2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.