CVE-2026-32836 describes an uncontrolled memory allocation vulnerability in mackron dr_libs dr_flac.h versions 0.13.3 and earlier, specifically within the drflac__read_and_decode_metadata() function. This flaw allows attackers to trigger excessive memory allocation by supplying crafted FLAC streams containing malicious PICTURE metadata blocks. Exploitation, which is a local attack requiring low privileges and no user interaction, can lead to a denial of service through memory exhaustion, reflected by a CVSS score of 5.5 (Medium). There is currently no evidence of active exploitation, nor is the vulnerability listed on CISA's KEV catalog or Hot List. No public exploit code is available, and there is no community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.13.3CPE matchmatch criteria | cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.