Impact
FluidSynth parses SoundFont 2 files, and from versions 2.5.0 through 2.5.6 it calculates the number of DMOD modulator records by dividing the chunk size by the modulator record size and subtracting one. A crafted SF2 file containing a DMOD chunk with zero size causes the unsigned subtraction to wrap to the maximum unsigned integer. The parser then attempts to allocate billions of SFMod structures, exhausting memory and causing the process to terminate, which results in a denial of service. This vulnerability is identified as a classical unsigned underflow weakness (CWE‑191).
Affected Systems
It affects the FluidSynth synthesizer software under the name FluidSynth, specifically all releases from version 2.5.0 up to but excluding 2.5.6. The vulnerability is resolved in FluidSynth version 2.5.6 and later, which correctly rejects zero‑sized DMOD chunks.
Risk and Exploitability
The CVSS score is 6.2, indicating medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves supplying a crafted SF2 file to a running FluidSynth process. An attacker who can provide such a file can force the synthesizer to consume all available memory, leading to a denial of service. Because the vulnerability is triggered by file input rather than a network interface, the impact is confined to hosts where FluidSynth is executed with that file; however, denial of service on critical audio services could disrupt operations.
OpenCVE Enrichment