Impact
FluidSynth’s native DLS loader, used in versions 2.5.0 through 2.5.5, assigns sample loop parameters directly from a DLS file without prior validation or sanitization. A crafted DLS file can place loop start or length values beyond the sample buffer, triggering out‑of‑bounds reads during audio rendering. This produces undefined behavior, which can manifest as a denial of service or the disclosure of memory contents, corresponding to a heap‑based buffer overrun weakness. The flaw is identified as CWE‑122 and CWE‑125.
Affected Systems
All builds of FluidSynth from 2.5.0 up to 2.5.5 are vulnerable when compiled with the CMake option enable‑native‑dls set to ON. Versions 2.5.6 and newer contain the fix, and any build compiled with enable‑native‑dls set to OFF does not expose the parser. The issue therefore applies to systems that load DLS files using an affected binary from the 2.5.x series.
Risk and Exploitability
The CVSS score of 8 reflects a high severity vulnerability. The EPSS score is not available, and the flaw is not catalogued in the CISA KEV list, suggesting no widespread exploitation yet. Based on the description, it is inferred that the attack vector is local: an attacker only needs the ability to supply a malicious DLS file to a user or a process that employs FluidSynth. Consequently, any environment accepting untrusted audio files is at risk. The potential impact ranges from service interruption to partial memory disclosure, demanding prompt remediation.
OpenCVE Enrichment