Out-of-Bounds Read Vulnerability in FluidSynth Synthesizer by FluidSynth
CVE-2026-61721
8HIGH
What is CVE-2026-61721?
FluidSynth, a software synthesizer adhering to the SoundFont 2 specifications, has a vulnerability between versions 2.5.0 and 2.5.6. The native DLS loader may improperly handle file-controlled wsmp.loop_start and wsmp.loop_length values, leading to potential out-of-bounds reads during audio rendering. This could result in undefined behavior and possible memory disclosure, raising serious security concerns. Users are advised to upgrade to version 2.5.6, where this issue is resolved. It’s also important to note that builds compiled without the native DLS option enabled are not susceptible to this vulnerability.
Affected Version(s)
fluidsynth >= 2.5.0, < 2.5.6
