Impact
FluidSynth’s command handler processes a pitch_bend_range command without validating the channel argument. An out‑of‑range channel value can be written outside the intended bounds, creating a heap-based buffer overrun that may trigger denial of service or, in a worst‑case scenario, allow arbitrary code execution. The vulnerability is rooted in CWE‑122 and directly affects the core synthesizer logic.
Affected Systems
Affected vendors and products include FluidSynth:fluidsynth for releases from 1.1.2 up to and including 2.5.6. The flaw is exploitable when the TCP server is enabled via new_fluid_server() or when the server is run with the –s option, as well as when a malicious user sends commands to the FluidSynth shell via standard input. Applications that do not use the shell, command handler, or TCP server are not impacted.
Risk and Exploitability
The CVSS score of 9.8 marks this issue as critical, indicating severe impact. EPSS data is unavailable, so exploit probability cannot be quantified from that metric, but the flaw is not listed in CISA’s KEV catalog, which may imply limited known exploitation to date. Nonetheless, the flaw is remotely reachable when the TCP interface is enabled and locally reachable through the shell, meaning both internal and external attackers could potentially prepare and send malicious commands. Given the lack of input bounds checking, a successful exploitation could lead to denial of service or code execution on the host running FluidSynth.
OpenCVE Enrichment