CVE-2025-14369Patch

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-14); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-14: 3Mentions · 2026-06-13: 1Patch / Workaround · 2026-03-14: 3Patch / Workaround · 2026-06-13: 1Technical Details · 2026-03-14: 203-1406-13
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-143
Disclosure1Patch2
2026-06-131
Patch1
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 A vulnerabilidade CVE-2025-14369 no sdl2_sound do Mageia foi corrigida, mas o aprendizado é atemporal. Aprenda a identificar, corrigir e mitigar falhas de segurança como um profissional. Saiba mais: -> http://tinyurl.com/2xrud4bd #Mageia https://t.co/joJmzkF76Y

    Post summary

    A patch has been released for CVE-2025-14369 affecting Mageia's sdl2_sound, with no evidence of active exploitation or PoC details.

    1000061
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Heads-up, Fedora community! 🐧A new security advisory is out for Fedora 43 addressing CVE-2025-14369 in SDL3_sound. This isn't a theoretical issue—it's a real integer overflow in FLAC decoding that can lead to service crashes. Read more: 👉 https://tinyurl.com/bduzzk8w #Security https://t.co/iNzxVL9lPB

    Post summary

    Fedora 43 has issued an advisory for CVE-2025-14369, highlighting an integer overflow in FLAC decoding that can crash services and pointing to the advisory for more information.

    00000183
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Just a heads-up for the Fedora community on Bluesky: A new update patches CVE-2025-14369 in SDL2_sound. Read more:👉 https://tinyurl.com/4k37vysw #Fedora #Security https://t.co/rWJfgWGNqy

    Post summary

    The tweet announces that Fedora’s latest update includes a fix for CVE‑2025‑14369 in SDL2_sound, urging users to apply the patch.

    00000166
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    CVE-2025-14369 critical DoS flaw in SDL_sound on Fedora 44 allows service disruption via integer overflow in FLAC metadata. Patches for SDL2_sound and SDL3_sound released March 5 2026, update now. #Vulnerability https://threatcluster.io/cluster/fedora-44-sdl_sound-denial-of-service-vulnerability-cve-2025-80abc2fc

    Post summary

    CVE-2025-14369 is a critical DoS vulnerability in SDL_sound on Fedora 44 caused by integer overflow in FLAC metadata; patches for SDL2_sound and SDL3_sound were released on March 5 2026.

    00000201
    101 followersView on X

Explore more