Description
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop points beyond the sample buffer, causing out-of-bounds reads during audio rendering, undefined behavior, possible memory disclosure, and denial of service. Builds compiled with the CMake option enable-native-dls set to OFF do not expose the affected parser. This issue is fixed in version 2.5.6.
Published: 2026-09-18
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service and possible memory disclosure
Action: Immediate Patch
AI Analysis

Impact

FluidSynth’s native DLS loader, used in versions 2.5.0 through 2.5.5, assigns sample loop parameters directly from a DLS file without prior validation or sanitization. A crafted DLS file can place loop start or length values beyond the sample buffer, triggering out‑of‑bounds reads during audio rendering. This produces undefined behavior, which can manifest as a denial of service or the disclosure of memory contents, corresponding to a heap‑based buffer overrun weakness. The flaw is identified as CWE‑122 and CWE‑125.

Affected Systems

All builds of FluidSynth from 2.5.0 up to 2.5.5 are vulnerable when compiled with the CMake option enable‑native‑dls set to ON. Versions 2.5.6 and newer contain the fix, and any build compiled with enable‑native‑dls set to OFF does not expose the parser. The issue therefore applies to systems that load DLS files using an affected binary from the 2.5.x series.

Risk and Exploitability

The CVSS score of 8 reflects a high severity vulnerability. The EPSS score is not available, and the flaw is not catalogued in the CISA KEV list, suggesting no widespread exploitation yet. Based on the description, it is inferred that the attack vector is local: an attacker only needs the ability to supply a malicious DLS file to a user or a process that employs FluidSynth. Consequently, any environment accepting untrusted audio files is at risk. The potential impact ranges from service interruption to partial memory disclosure, demanding prompt remediation.

Generated by OpenCVE AI on September 19, 2026 at 11:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FluidSynth to version 2.5.6 or later.
  • Recompile the existing FluidSynth source with the CMake flag enable‑native‑dls set to OFF to disable the vulnerable parser.
  • Validate all externally supplied DLS files and reject any that contain loop points outside the sample bounds before feeding them to FluidSynth.

Generated by OpenCVE AI on September 19, 2026 at 11:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Fluidsynth
Fluidsynth fluidsynth
Vendors & Products Fluidsynth
Fluidsynth fluidsynth

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop points beyond the sample buffer, causing out-of-bounds reads during audio rendering, undefined behavior, possible memory disclosure, and denial of service. Builds compiled with the CMake option enable-native-dls set to OFF do not expose the affected parser. This issue is fixed in version 2.5.6.
Title FluidSynth: Heap-based buffer overrun for DLS samples
Weaknesses CWE-122
CWE-125
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Fluidsynth Fluidsynth
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:21:42.856Z

Reserved: 2026-07-10T18:51:13.920Z

Link: CVE-2026-61721

cve-icon Vulnrichment

Updated: 2026-09-18T20:21:39.282Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:18.567

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-61721

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:00:12Z

Weaknesses