Executive brief
dr_flac is a popular C library used for decoding FLAC audio files. A vulnerability in how it handles audio metadata allows a specially crafted file to force the application to request massive amounts of system memory (up to 4GB). This can lead to the application crashing or the entire system becoming unresponsive, resulting in a denial of service.
Technical details
An uncontrolled memory allocation vulnerability (CWE-789) exists in the drflac__read_and_decode_metadata() function within dr_flac.h. The root cause is a failure to validate the mimeLength and descriptionLength fields against the actual remaining block size before performing a malloc() call. An attacker can provide a crafted FLAC stream with a PICTURE metadata block containing large length values, forcing an allocation of up to 4 GiB from a very small input. This vulnerability specifically affects entry points using drflac_open_*_with_metadata() when a non-NULL metadata callback is provided. The issue has been addressed in commits fefced4, 4f5a4cd, and 663239a.
Affected products
- mackron dr_libs dr_flac.h 0.13.3 and earlier
Timeline
- 2026-03-17: advisory: NVD publication date
- 2026-03-17: disclosed: GitHub issue 298 opened
- 2026-03-17: patched: Fixes committed to repository
References
- https://github.com/mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100a
- https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676
- https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8
- https://github.com/mackron/dr_libs/issues/298
- https://www.vulncheck.com/advisories/mackron-dr-libs-excessive-memory-allocation-in-picture-metadata-parsing