flac is vulnerable to information disclosure. A remote authenticated attacker is able to gain access to disclosure of sensitive user information via a possible out of bounds write due to a missing bounds check.
lists.debian.org/debian-lts-announce/2022/03/msg00022.html
lists.debian.org/debian-lts-announce/2022/09/msg00003.html
lists.fedoraproject.org/archives/list/[email protected]/message/EWXBVMPPSL377I7YM55ZYXVKVMYOKES2/
lists.fedoraproject.org/archives/list/[email protected]/message/Q4Y7BW35TGNFYBYBSBDSGLUJHHTYEUSG/
secdb.alpinelinux.org/edge/main.yaml
secdb.alpinelinux.org/v3.12/main.yaml
secdb.alpinelinux.org/v3.13/main.yaml
secdb.alpinelinux.org/v3.14/main.yaml
secdb.alpinelinux.org/v3.15/main.yaml
source.android.com/security/bulletin/pixel/2021-06-01