Impact
The vulnerability lies in FluidSynth’s native DLS parser, which checks articulation chunk sizes using an unsigned calculation that combines the chunk size with the number of connection blocks. The parser does not constrain the multiplication and addition to remain within 32‑bit limits. A crafted DLS file can supply a large connection‑block count that causes the size expression to wrap around, bypassing the chunk‑size check. The parser then proceeds to read a large amount of data—up to roughly one billion 12‑byte iterations—beyond the chunk boundary, resulting in excessive CPU usage and invalid reads that can lead to a denial‑of‑service condition.
Affected Systems
FluidSynth versions 2.5.0 through 2.5.6, inclusive, are affected because they include the vulnerable native DLS parser. Builds that were compiled with the CMake option enable‑native‑dls set to OFF do not expose the parser. Versions newer than 2.5.6 contain the repair that limits the calculation and prevents the overflow, and therefore are not vulnerable.
Risk and Exploitability
The CVSS score of 6.8 classifies the flaw as medium severity. EPSS data is not available, so the probability of exploitation remains unknown, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a crafted DLS file to be parsed by FluidSynth. The CVE description does not state whether the application can load DLS files from a network source; it is unclear if a remote interface exists. Based on the description, it is inferred that if a remote interface for loading DLS files were present, an attacker could supply a malicious file, but this is not confirmed. Consequently, an attacker must either supply the file locally or rely on an undocumented remote loading capability. The flaw does not provide remote code execution or privilege escalation; the impact is limited to denial of service via invalid reads and exhaustion of processing resources.
OpenCVE Enrichment