Junglewise Threat Intelligence

CVE-2026-32836: mackron dr_libs uncontrolled memory allocation in dr_flac.h

CVE-2026-32836 · Severity: medium · CVSS 6.2 · Published 2026-03-17

Executive brief

dr_flac is a popular C library used for decoding FLAC audio files. A vulnerability in how it handles audio metadata allows a specially crafted file to force the application to request massive amounts of system memory (up to 4GB). This can lead to the application crashing or the entire system becoming unresponsive, resulting in a denial of service.

Technical details

An uncontrolled memory allocation vulnerability (CWE-789) exists in the drflac__read_and_decode_metadata() function within dr_flac.h. The root cause is a failure to validate the mimeLength and descriptionLength fields against the actual remaining block size before performing a malloc() call. An attacker can provide a crafted FLAC stream with a PICTURE metadata block containing large length values, forcing an allocation of up to 4 GiB from a very small input. This vulnerability specifically affects entry points using drflac_open_*_with_metadata() when a non-NULL metadata callback is provided. The issue has been addressed in commits fefced4, 4f5a4cd, and 663239a.

Affected products

  • mackron dr_libs dr_flac.h 0.13.3 and earlier

Timeline

  • 2026-03-17: advisory: NVD publication date
  • 2026-03-17: disclosed: GitHub issue 298 opened
  • 2026-03-17: patched: Fixes committed to repository

References

Related threats