Out-of-Bounds Read Vulnerability in FluidSynth Synthesizer by FluidSynth
CVE-2026-61721

8HIGH

Key Information:

Vendor

Fluidsynth

Vendor
CVE Published:
18 September 2026

What is CVE-2026-61721?

FluidSynth, a software synthesizer adhering to the SoundFont 2 specifications, has a vulnerability between versions 2.5.0 and 2.5.6. The native DLS loader may improperly handle file-controlled wsmp.loop_start and wsmp.loop_length values, leading to potential out-of-bounds reads during audio rendering. This could result in undefined behavior and possible memory disclosure, raising serious security concerns. Users are advised to upgrade to version 2.5.6, where this issue is resolved. It’s also important to note that builds compiled without the native DLS option enabled are not susceptible to this vulnerability.

Affected Version(s)

fluidsynth >= 2.5.0, < 2.5.6

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.