DLS Parser Issue in FluidSynth Affects Versions 2.5.0 to 2.5.6
CVE-2026-61722
6.8MEDIUM
What is CVE-2026-61722?
A vulnerability exists in FluidSynth's DLS parser that allows a crafted DLS file to exploit arithmetic overflow in the validation process. This can lead to excessive resource consumption and potentially cause a denial of service due to the parser executing an enormous number of iterations beyond the intended chunk boundary. Users are advised to update to version 2.5.6, where the issue has been resolved.
Affected Version(s)
fluidsynth >= 2.5.0, < 2.5.6
