Description
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A crafted SF2 file containing a zero-sized DMOD chunk makes the unsigned subtraction wrap to UINT_MAX, and the parser then attempts billions of SFMod allocations. This exhausts process memory and causes denial of service. No workaround is available. This issue is fixed in version 2.5.6.
Published: 2026-09-18
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

FluidSynth parses SoundFont 2 files, and from versions 2.5.0 through 2.5.6 it calculates the number of DMOD modulator records by dividing the chunk size by the modulator record size and subtracting one. A crafted SF2 file containing a DMOD chunk with zero size causes the unsigned subtraction to wrap to the maximum unsigned integer. The parser then attempts to allocate billions of SFMod structures, exhausting memory and causing the process to terminate, which results in a denial of service. This vulnerability is identified as a classical unsigned underflow weakness (CWE‑191).

Affected Systems

It affects the FluidSynth synthesizer software under the name FluidSynth, specifically all releases from version 2.5.0 up to but excluding 2.5.6. The vulnerability is resolved in FluidSynth version 2.5.6 and later, which correctly rejects zero‑sized DMOD chunks.

Risk and Exploitability

The CVSS score is 6.2, indicating medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves supplying a crafted SF2 file to a running FluidSynth process. An attacker who can provide such a file can force the synthesizer to consume all available memory, leading to a denial of service. Because the vulnerability is triggered by file input rather than a network interface, the impact is confined to hosts where FluidSynth is executed with that file; however, denial of service on critical audio services could disrupt operations.

Generated by OpenCVE AI on September 19, 2026 at 10:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official FluidSynth 2.5.6 or later release to replace vulnerable versions.
  • Pre‑validate any SoundFont files by checking chunk sizes and structure before loading them into FluidSynth to avoid processing malformed data.
  • Run FluidSynth inside a confined environment or set system resource limits to mitigate excessive memory consumption in the event of an attack.

Generated by OpenCVE AI on September 19, 2026 at 10:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Fluidsynth
Fluidsynth fluidsynth
Vendors & Products Fluidsynth
Fluidsynth fluidsynth

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A crafted SF2 file containing a zero-sized DMOD chunk makes the unsigned subtraction wrap to UINT_MAX, and the parser then attempts billions of SFMod allocations. This exhausts process memory and causes denial of service. No workaround is available. This issue is fixed in version 2.5.6.
Title FluidSynth: SF2 DMOD Chunk Unsigned Underflow
Weaknesses CWE-191
References
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Fluidsynth Fluidsynth
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T16:27:25.573Z

Reserved: 2026-07-10T18:51:13.920Z

Link: CVE-2026-61720

cve-icon Vulnrichment

Updated: 2026-09-21T16:27:18.979Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T20:17:18.420

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-61720

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses
  • CWE-191

    Integer Underflow (Wrap or Wraparound)