Security Advisory

CVE-2025-14369

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-20 11:49:08
Last updated 2026-01-20 14:33:15
Assigner certcc
State PUBLISHED

Description

dr_flac, an audio decoder within the dr_libs toolset, contains an integer overflow vulnerability flaw due to trusting the totalPCMFrameCount field from FLAC metadata before calculating buffer size, allowing an attacker with a specially crafted file to perform DoS against programs using the tool.