Description
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that the multiplication and addition fit in 32 bits. A crafted DLS file can supply a large connblocks value that wraps the expression and bypasses the chunk-size check, after which the parser performs approximately one billion 12-byte iterations beyond the chunk boundary. The excessive processing and invalid reads can cause denial of service. Builds with the CMake option enable-native-dls set to OFF do not expose the parser. This issue is fixed in version 2.5.6.
Published: 2026-09-18
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability lies in FluidSynth’s native DLS parser, which checks articulation chunk sizes using an unsigned calculation that combines the chunk size with the number of connection blocks. The parser does not constrain the multiplication and addition to remain within 32‑bit limits. A crafted DLS file can supply a large connection‑block count that causes the size expression to wrap around, bypassing the chunk‑size check. The parser then proceeds to read a large amount of data—up to roughly one billion 12‑byte iterations—beyond the chunk boundary, resulting in excessive CPU usage and invalid reads that can lead to a denial‑of‑service condition.

Affected Systems

FluidSynth versions 2.5.0 through 2.5.6, inclusive, are affected because they include the vulnerable native DLS parser. Builds that were compiled with the CMake option enable‑native‑dls set to OFF do not expose the parser. Versions newer than 2.5.6 contain the repair that limits the calculation and prevents the overflow, and therefore are not vulnerable.

Risk and Exploitability

The CVSS score of 6.8 classifies the flaw as medium severity. EPSS data is not available, so the probability of exploitation remains unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a crafted DLS file to be parsed by FluidSynth. The CVE description does not state whether the application can load DLS files from a network source; it is unclear if a remote interface exists. Based on the description, it is inferred that if a remote interface for loading DLS files were present, an attacker could supply a malicious file, but this is not confirmed. Consequently, an attacker must either supply the file locally or rely on an undocumented remote loading capability. The flaw does not provide remote code execution or privilege escalation; the impact is limited to denial of service via invalid reads and exhaustion of processing resources.

Generated by OpenCVE AI on September 19, 2026 at 11:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FluidSynth to version 2.5.6 or later, which enforces the overflow check and fixes the DLS parsing bug.
  • If an upgrade is not feasible, rebuild or reconfigure the application with the CMake option enable‑native‑dls set to OFF to eliminate the vulnerable parser entirely.
  • Restrict the source of DLS files, ensuring that untrusted files are not loaded automatically or apply input validation before parsing.

Generated by OpenCVE AI on September 19, 2026 at 11:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 03:00:00 +0000

Type Values Removed Values Added
First Time appeared Fluidsynth
Fluidsynth fluidsynth
Vendors & Products Fluidsynth
Fluidsynth fluidsynth

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without first ensuring that the multiplication and addition fit in 32 bits. A crafted DLS file can supply a large connblocks value that wraps the expression and bypasses the chunk-size check, after which the parser performs approximately one billion 12-byte iterations beyond the chunk boundary. The excessive processing and invalid reads can cause denial of service. Builds with the CMake option enable-native-dls set to OFF do not expose the parser. This issue is fixed in version 2.5.6.
Title FluidSynth: DLS Articulation Chunk Integer Overflow
Weaknesses CWE-190
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}


Subscriptions

Fluidsynth Fluidsynth
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-22T15:44:05.935Z

Reserved: 2026-07-10T18:51:13.921Z

Link: CVE-2026-61722

cve-icon Vulnrichment

Updated: 2026-09-22T15:43:57.232Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:18.713

Modified: 2026-09-23T18:28:25.093

Link: CVE-2026-61722

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T02:45:18Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound