Denial of Service Vulnerability in FluidSynth Software Synthesizer
CVE-2026-61720

6.2MEDIUM

Key Information:

Vendor

Fluidsynth

Vendor
CVE Published:
18 September 2026

What is CVE-2026-61720?

FluidSynth versions 2.5.0 through 2.5.6 are vulnerable to a denial of service condition caused by the SF2 parser incorrectly handling DMOD modulator counts. The parser computes the count without validating chunk sizes, allowing a crafted SF2 file with a zero-sized DMOD chunk to lead to unsigned integer wraparound. This results in excessive memory allocation attempts, potentially exhausting system memory and causing application crashes. The issue is resolved in version 2.5.6, and users are urged to update to this version as no workaround is available.

Affected Version(s)

fluidsynth >= 2.5.0, < 2.5.6

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.