CVE-2025-14369: Mackron Dr Flac

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.

Affected products

  • Mackron Dr Flac: up to and including 0.13.2

Published 2026-01-20. Last modified 2026-06-17.