Description
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible code execution. The issue is remotely reachable when the TCP server is enabled through new_fluid_server() or fluidsynth -s, and it is locally reachable through malicious commands delivered to the FluidSynth shell on standard input. Applications that do not use the shell, command handler, or TCP server are not affected. This issue is fixed in version 2.5.6.
Published: 2026-09-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Potential code execution or denial of service
Action: Immediate Patch
AI Analysis

Impact

FluidSynth’s command handler processes a pitch_bend_range command without validating the channel argument. An out‑of‑range channel value can be written outside the intended bounds, creating a heap-based buffer overrun that may trigger denial of service or, in a worst‑case scenario, allow arbitrary code execution. The vulnerability is rooted in CWE‑122 and directly affects the core synthesizer logic.

Affected Systems

Affected vendors and products include FluidSynth:fluidsynth for releases from 1.1.2 up to and including 2.5.6. The flaw is exploitable when the TCP server is enabled via new_fluid_server() or when the server is run with the –s option, as well as when a malicious user sends commands to the FluidSynth shell via standard input. Applications that do not use the shell, command handler, or TCP server are not impacted.

Risk and Exploitability

The CVSS score of 9.8 marks this issue as critical, indicating severe impact. EPSS data is unavailable, so exploit probability cannot be quantified from that metric, but the flaw is not listed in CISA’s KEV catalog, which may imply limited known exploitation to date. Nonetheless, the flaw is remotely reachable when the TCP interface is enabled and locally reachable through the shell, meaning both internal and external attackers could potentially prepare and send malicious commands. Given the lack of input bounds checking, a successful exploitation could lead to denial of service or code execution on the host running FluidSynth.

Generated by OpenCVE AI on September 19, 2026 at 10:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FluidSynth to version 2.5.6 or later where the code has been fixed.
  • If you must use the TCP server, ensure it is only listening on trusted interfaces and/or restrict access with firewall rules.
  • Avoid using the FluidSynth shell or command handler with untrusted or external input; if possible, disable the shell by compiling without the shell support or by not exposing it to unauthenticated clients.

Generated by OpenCVE AI on September 19, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Fluidsynth
Fluidsynth fluidsynth
Vendors & Products Fluidsynth
Fluidsynth fluidsynth

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible code execution. The issue is remotely reachable when the TCP server is enabled through new_fluid_server() or fluidsynth -s, and it is locally reachable through malicious commands delivered to the FluidSynth shell on standard input. Applications that do not use the shell, command handler, or TCP server are not affected. This issue is fixed in version 2.5.6.
Title FluidSynth: Heap-based buffer overrun
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Fluidsynth Fluidsynth
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:47:56.341Z

Reserved: 2026-06-29T21:54:30.331Z

Link: CVE-2026-58264

cve-icon Vulnrichment

Updated: 2026-09-21T20:44:18.258Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:18.107

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-58264

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow