Null Pointer Dereference in FluidSynth Affects Multiple Versions
CVE-2025-56225
7.5HIGH
What is CVE-2025-56225?
FluidSynth versions 2.4.6 and earlier are susceptible to a null pointer dereference vulnerability located within the fluid_synth_monopoly.c file. This vulnerability can be triggered when an invalid MIDI file is loaded, potentially causing the application to crash and resulting in service disruption. This issue emphasizes the importance of validating input files and implementing proper error handling to mitigate risks associated with malformed MIDI data.
