Description
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, or availability. No crafted MIDI file is required because the unsafe condition is created by the channel-count configuration itself. Keeping synth.midi-channels at its default value of 16 avoids the vulnerable path. This issue is fixed in version 2.5.6.
Published: 2026-09-18
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Out-of-bounds memory corruption potentially affecting confidentiality, integrity, or availability via an unsafe MIDI channel count configuration
Action: Immediate Patch
AI Analysis

Impact

FluidSynth versions 2.2.4 through 2.5.6 allow a configuration value, synth.midi-channels, to be set above the intended limit of 16. When a larger value is used, the MIDI player accesses a heap variable outside its allocated bounds, producing out-of-bounds reads and writes. This undefined behavior can compromise confidentiality, integrity, or availability by corrupting program memory or enabling an attacker to influence execution flow.

Affected Systems

The vulnerability affects the FluidSynth synthesizer, a software rendering system based on the SoundFont 2 specification. Any system that installed FluidSynth between version 2.2.4 and 2.5.6 and configured synth.midi-channels beyond 16 is impacted. The issue was resolved in version 2.5.6, so versions 2.5.6 and later are not affected.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while no EPSS score is available and the vulnerability is not listed in CISA's KEV catalog. The exploitability requires the channel count configuration to be altered beyond the default value of 16; no crafted MIDI file is needed. From the information given, this likely requires local access to the configuration or remote control of the synthesizer application. The vulnerability can lead to arbitrary memory corruption and potential code execution, making it critical for users who run FluidSynth with a modified channel count.

Generated by OpenCVE AI on September 19, 2026 at 10:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FluidSynth to version 2.5.6 or later, which contains the patch that removes the out-of-bounds access
  • If upgrading is not immediately possible, enforce the default configuration by setting synth.midi-channels to 16 or lowering it to a safe value
  • Verify that the configuration file used by FluidSynth does not expose the synth.midi-channels setting to untrusted input sources

Generated by OpenCVE AI on September 19, 2026 at 10:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 26 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Fluidsynth
Fluidsynth fluidsynth
Vendors & Products Fluidsynth
Fluidsynth fluidsynth

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, or availability. No crafted MIDI file is required because the unsafe condition is created by the channel-count configuration itself. Keeping synth.midi-channels at its default value of 16 avoids the vulnerable path. This issue is fixed in version 2.5.6.
Title FluidSynth: Heap Buffer Overflow in MIDI Player
Weaknesses CWE-122
CWE-125
CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Fluidsynth Fluidsynth
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-25T16:13:08.897Z

Reserved: 2026-07-10T18:51:13.920Z

Link: CVE-2026-61714

cve-icon Vulnrichment

Updated: 2026-09-25T16:13:04.679Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:18.270

Modified: 2026-09-25T17:17:09.700

Link: CVE-2026-61714

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T00:00:12Z

Weaknesses