Impact
FluidSynth versions 2.2.4 through 2.5.6 allow a configuration value, synth.midi-channels, to be set above the intended limit of 16. When a larger value is used, the MIDI player accesses a heap variable outside its allocated bounds, producing out-of-bounds reads and writes. This undefined behavior can compromise confidentiality, integrity, or availability by corrupting program memory or enabling an attacker to influence execution flow.
Affected Systems
The vulnerability affects the FluidSynth synthesizer, a software rendering system based on the SoundFont 2 specification. Any system that installed FluidSynth between version 2.2.4 and 2.5.6 and configured synth.midi-channels beyond 16 is impacted. The issue was resolved in version 2.5.6, so versions 2.5.6 and later are not affected.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while no EPSS score is available and the vulnerability is not listed in CISA's KEV catalog. The exploitability requires the channel count configuration to be altered beyond the default value of 16; no crafted MIDI file is needed. From the information given, this likely requires local access to the configuration or remote control of the synthesizer application. The vulnerability can lead to arbitrary memory corruption and potential code execution, making it critical for users who run FluidSynth with a modified channel count.
OpenCVE Enrichment