Memory Allocation Vulnerability in dr_libs by Mackron
CVE-2026-32836

6.9MEDIUM

Key Information:

Vendor

Mackron

Vendor
CVE Published:
17 March 2026

What is CVE-2026-32836?

The dr_libs library versions 0.13.3 and earlier are vulnerable to an uncontrolled memory allocation issue within the drflac__read_and_decode_metadata() function. This vulnerability can be exploited by attackers through crafting malicious PICTURE metadata blocks, specifically manipulating the mimeLength and descriptionLength fields. Such exploits can lead to a denial of service condition due to excessive memory allocation when processing FLAC streams that utilize metadata callbacks, which ultimately impact application stability.

Affected Version(s)

dr_libs dr_flac.h 0 <= 0.13.3

dr_libs dr_flac.h fefced4a64adfb1a68a2d31d882366e56096dee8

dr_libs dr_flac.h 4f5a4cd3b57564d969443c580c75857e039f100a

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ana Kapulica
.