CVE-2026-32836

Source
https://cve.org/CVERecord?id=CVE-2026-32836
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32836.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-32836
Downstream
Published
2026-03-17T19:10:19.404Z
Modified
2026-07-28T08:13:29.686416Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
mackron / dr_libs dr_flac.h Excessive Memory Allocation in PICTURE Metadata Parsing
Details

drlibs drflac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac_readanddecodemetadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32836.json",
    "cwe_ids": [
        "CWE-789"
    ]
}
References

Affected packages

Git / github.com/mackron/dr_libs

Affected ranges

Type
GIT
Repo
https://github.com/mackron/dr_libs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.13.3"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

flac-0.*
flac-0.12.43
flac-0.13.0
flac-0.13.1
flac-0.13.2
flac-0.13.3
mp3-0.*
mp3-0.6.40
mp3-0.7.0
mp3-0.7.1
mp3-0.7.2
mp3-0.7.3
wav-0.*
wav-0.13.17
wav-0.14.0
wav-0.14.1
wav-0.14.2
wav-0.14.3
wav-0.14.4
wav-0.14.5

Database specific

vanir_signatures_modified
"2026-07-28T08:13:29Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32836.json"
vanir_signatures
[
    {
        "signature_type": "Function",
        "target": {
            "file": "dr_flac.h",
            "function": "drflac__read_and_decode_metadata"
        },
        "deprecated": false,
        "digest": {
            "length": 10723.0,
            "function_hash": "263877883709673697127533507054059527641"
        },
        "signature_version": "v1",
        "source": "https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676",
        "id": "CVE-2026-32836-433925cb"
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "dr_flac.h",
            "function": "drflac__read_and_decode_metadata"
        },
        "deprecated": false,
        "digest": {
            "length": 10815.0,
            "function_hash": "231439137947889826121592771963988490315"
        },
        "signature_version": "v1",
        "source": "https://github.com/mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100a",
        "id": "CVE-2026-32836-4b6dedd5"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "dr_flac.h"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "239453336896498647652828486810239642674",
                "46576341553487246220612096141880806594",
                "316137208537675378201811604300593086587",
                "256710093781893194579228782733319349911",
                "326170709788470511574172942760317697619",
                "277637927234007055121583992636272992437",
                "170455584214542869459599082284592249221",
                "297373028930806465255451570640489466189",
                "166357148870445037158725702856976685784"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8",
        "id": "CVE-2026-32836-75e6274e"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "dr_flac.h"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "312098584394681776007184099119548608788",
                "156795787947303449052969177408990759377",
                "230589701935222855554839073967535236708",
                "79555147284346167299777022351548481719",
                "75352035980912294100526432300105411848",
                "283318800769506464223620764598937038807",
                "160366924805719731352282503008834715765",
                "193551421593112871500734533425905952506",
                "127393314191519298840106846926157382787",
                "60984747867211332558045335830138746820",
                "311472631558505686306470143602637292431",
                "290877997238418456864023098957039727430",
                "263529883509795293594817901859378992771",
                "103137645577131216360093940240659123655"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676",
        "id": "CVE-2026-32836-b967df33"
    },
    {
        "signature_type": "Line",
        "target": {
            "file": "dr_flac.h"
        },
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "255914025200550521242955536198361949313",
                "56708265354896710900107644452192083880",
                "5770782863631961488488291778584920071",
                "70132874111854299496485695227363532908",
                "4112223776895019611132594392831616021",
                "325484742618797397502173826220250251839",
                "186653042841668445497522259904937439702",
                "264275320579232980514321199460253201387",
                "37972100844841978449938064050499965505",
                "131648391650571329105268890151881489483",
                "264122046991060135958074768807838543257",
                "103137645577131216360093940240659123655"
            ]
        },
        "signature_version": "v1",
        "source": "https://github.com/mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100a",
        "id": "CVE-2026-32836-cb792255"
    },
    {
        "signature_type": "Function",
        "target": {
            "file": "dr_flac.h",
            "function": "drflac__read_and_decode_metadata"
        },
        "deprecated": false,
        "digest": {
            "length": 10769.0,
            "function_hash": "242963734227876497380352942408454134200"
        },
        "signature_version": "v1",
        "source": "https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8",
        "id": "CVE-2026-32836-d4399a31"
    }
]