DLS Parser Issue in FluidSynth Affects Versions 2.5.0 to 2.5.6
CVE-2026-61722

6.8MEDIUM

Key Information:

Vendor

Fluidsynth

Vendor
CVE Published:
18 September 2026

What is CVE-2026-61722?

A vulnerability exists in FluidSynth's DLS parser that allows a crafted DLS file to exploit arithmetic overflow in the validation process. This can lead to excessive resource consumption and potentially cause a denial of service due to the parser executing an enormous number of iterations beyond the intended chunk boundary. Users are advised to update to version 2.5.6, where the issue has been resolved.

Affected Version(s)

fluidsynth >= 2.5.0, < 2.5.6

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.