{"id":"CVE-2026-32836","summary":"mackron / dr_libs dr_flac.h Excessive Memory Allocation in PICTURE Metadata Parsing","details":"dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.","modified":"2026-08-12T15:32:28.561801Z","published":"2026-03-17T19:10:19.404Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-789"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32836.json"},"references":[{"type":"WEB","url":"https://github.com/mackron/dr_libs/blob/master/dr_flac.h"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/32xxx/CVE-2026-32836.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-32836"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/mackron-dr-libs-excessive-memory-allocation-in-picture-metadata-parsing"},{"type":"REPORT","url":"https://github.com/mackron/dr_libs/issues/298"},{"type":"FIX","url":"https://github.com/mackron/dr_libs/commit/4f5a4cd3b57564d969443c580c75857e039f100a"},{"type":"FIX","url":"https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676"},{"type":"FIX","url":"https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mackron/dr_libs","events":[{"introduced":"0"},{"fixed":"4f5a4cd3b57564d969443c580c75857e039f100a"},{"fixed":"663239a3d0460c33bd5b6e5166edcb404e3df676"},{"fixed":"fefced4a64adfb1a68a2d31d882366e56096dee8"}],"database_specific":{"cpe":"cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.13.3"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["wav-0.14.5","mp3-0.7.3","wav-0.14.4","flac-0.13.3","wav-0.14.3","wav-0.14.2","mp3-0.7.2","flac-0.13.2","wav-0.14.1","flac-0.13.1","mp3-0.7.1","wav-0.14.0","mp3-0.7.0","flac-0.13.0","wav-0.13.17","mp3-0.6.40","flac-0.12.43"],"database_specific":{"vanir_signatures":[{"target":{"file":"dr_flac.h","function":"drflac__read_and_decode_metadata"},"deprecated":false,"digest":{"function_hash":"263877883709673697127533507054059527641","length":10723},"id":"CVE-2026-32836-433925cb","signature_type":"Function","signature_version":"v1","source":"https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676"},{"target":{"file":"dr_flac.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["239453336896498647652828486810239642674","46576341553487246220612096141880806594","316137208537675378201811604300593086587","256710093781893194579228782733319349911","326170709788470511574172942760317697619","277637927234007055121583992636272992437","170455584214542869459599082284592249221","297373028930806465255451570640489466189","166357148870445037158725702856976685784"]},"id":"CVE-2026-32836-75e6274e","signature_type":"Line","signature_version":"v1","source":"https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8"},{"id":"CVE-2026-32836-b967df33","signature_type":"Line","signature_version":"v1","source":"https://github.com/mackron/dr_libs/commit/663239a3d0460c33bd5b6e5166edcb404e3df676","target":{"file":"dr_flac.h"},"deprecated":false,"digest":{"line_hashes":["312098584394681776007184099119548608788","156795787947303449052969177408990759377","230589701935222855554839073967535236708","79555147284346167299777022351548481719","75352035980912294100526432300105411848","283318800769506464223620764598937038807","160366924805719731352282503008834715765","193551421593112871500734533425905952506","127393314191519298840106846926157382787","60984747867211332558045335830138746820","311472631558505686306470143602637292431","290877997238418456864023098957039727430","263529883509795293594817901859378992771","103137645577131216360093940240659123655"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"242963734227876497380352942408454134200","length":10769},"id":"CVE-2026-32836-d4399a31","signature_type":"Function","signature_version":"v1","source":"https://github.com/mackron/dr_libs/commit/fefced4a64adfb1a68a2d31d882366e56096dee8","target":{"file":"dr_flac.h","function":"drflac__read_and_decode_metadata"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-32836.json","vanir_signatures_modified":"2026-08-12T15:32:28Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}