drlibs drflac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac_readanddecodemetadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.
{
"cna_assigner": "VulnCheck",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32836.json",
"cwe_ids": [
"CWE-789"
]
}{
"cpe": "cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "0.13.3"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-07-28T08:13:29Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32836.json"
[
{
"signature_type": "Function",
"target": {
"file": "dr_flac.h",
"function": "drflac__read_and_decode_metadata"
},
"deprecated": false,
"digest": {
"length": 10723.0,
"function_hash": "263877883709673697127533507054059527641"
},
"signature_version": "v1",
"source": "https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676",
"id": "CVE-2026-32836-433925cb"
},
{
"signature_type": "Function",
"target": {
"file": "dr_flac.h",
"function": "drflac__read_and_decode_metadata"
},
"deprecated": false,
"digest": {
"length": 10815.0,
"function_hash": "231439137947889826121592771963988490315"
},
"signature_version": "v1",
"source": "https://github.com/mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100a",
"id": "CVE-2026-32836-4b6dedd5"
},
{
"signature_type": "Line",
"target": {
"file": "dr_flac.h"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"239453336896498647652828486810239642674",
"46576341553487246220612096141880806594",
"316137208537675378201811604300593086587",
"256710093781893194579228782733319349911",
"326170709788470511574172942760317697619",
"277637927234007055121583992636272992437",
"170455584214542869459599082284592249221",
"297373028930806465255451570640489466189",
"166357148870445037158725702856976685784"
]
},
"signature_version": "v1",
"source": "https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8",
"id": "CVE-2026-32836-75e6274e"
},
{
"signature_type": "Line",
"target": {
"file": "dr_flac.h"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"312098584394681776007184099119548608788",
"156795787947303449052969177408990759377",
"230589701935222855554839073967535236708",
"79555147284346167299777022351548481719",
"75352035980912294100526432300105411848",
"283318800769506464223620764598937038807",
"160366924805719731352282503008834715765",
"193551421593112871500734533425905952506",
"127393314191519298840106846926157382787",
"60984747867211332558045335830138746820",
"311472631558505686306470143602637292431",
"290877997238418456864023098957039727430",
"263529883509795293594817901859378992771",
"103137645577131216360093940240659123655"
]
},
"signature_version": "v1",
"source": "https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676",
"id": "CVE-2026-32836-b967df33"
},
{
"signature_type": "Line",
"target": {
"file": "dr_flac.h"
},
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"255914025200550521242955536198361949313",
"56708265354896710900107644452192083880",
"5770782863631961488488291778584920071",
"70132874111854299496485695227363532908",
"4112223776895019611132594392831616021",
"325484742618797397502173826220250251839",
"186653042841668445497522259904937439702",
"264275320579232980514321199460253201387",
"37972100844841978449938064050499965505",
"131648391650571329105268890151881489483",
"264122046991060135958074768807838543257",
"103137645577131216360093940240659123655"
]
},
"signature_version": "v1",
"source": "https://github.com/mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100a",
"id": "CVE-2026-32836-cb792255"
},
{
"signature_type": "Function",
"target": {
"file": "dr_flac.h",
"function": "drflac__read_and_decode_metadata"
},
"deprecated": false,
"digest": {
"length": 10769.0,
"function_hash": "242963734227876497380352942408454134200"
},
"signature_version": "v1",
"source": "https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8",
"id": "CVE-2026-32836-d4399a31"
}
]