CVE-2026-32836Disclosure(mackron / dr_libs)

LOWCVSS 5.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger excessive memory allocation by supplying crafted PICTURE metadata blocks. Attackers can exploit attacker-controlled mimeLength and descriptionLength fields to cause denial of service through memory exhaustion when processing FLAC streams with metadata callbacks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-789

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dr_libs

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
dr_libs

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-17: 2Technical Details · 2026-03-17: 203-17
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32836 Uncontrolled Memory Allocation Vulnerability in dr_libs FLAC Meta... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32836 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    A new CVE (CVE-2026-32836) describes an uncontrolled memory allocation bug in dr_libs FLAC Meta, with links to detailed information but no proof‑of‑concept, exploit, or patch details.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32836 dr_libs version 0.13.3 and earlier contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_metadata() that allows attackers to trigger exce… https://www.cve.org/CVERecord?id=CVE-2026-32836

    Post summary

    A brief disclosure of CVE‑2026‑32836, noting an uncontrolled memory allocation flaw in dr_libs versions 0.13.3 and earlier, with a link to the full CVE record.

    0000072
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmackrondr_libs---

Explore more