Memory Allocation Vulnerability in dr_libs by Mackron
CVE-2026-32836
6.9MEDIUM
What is CVE-2026-32836?
The dr_libs library versions 0.13.3 and earlier are vulnerable to an uncontrolled memory allocation issue within the drflac__read_and_decode_metadata() function. This vulnerability can be exploited by attackers through crafting malicious PICTURE metadata blocks, specifically manipulating the mimeLength and descriptionLength fields. Such exploits can lead to a denial of service condition due to excessive memory allocation when processing FLAC streams that utilize metadata callbacks, which ultimately impact application stability.
Affected Version(s)
dr_libs dr_flac.h 0 <= 0.13.3
dr_libs dr_flac.h fefced4a64adfb1a68a2d31d882366e56096dee8
dr_libs dr_flac.h 4f5a4cd3b57564d969443c580c75857e039f100a
