dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
History

Tue, 20 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
Description dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.
Title CVE-2025-14369
References

cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-01-20T13:19:03.123Z

Reserved: 2025-12-09T18:31:22.317Z

Link: CVE-2025-14369

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-20T12:15:48.440

Modified: 2026-01-20T12:15:48.440

Link: CVE-2025-14369

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.