Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-58264— FluidSynth: Heap-based buffer overrun

Quick assessment

Affected
FluidSynth fluidsynth
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FluidSynth 是一款基于 SoundFont 2 规范的软件合成器。从 1.1.2 版本到 2.5.6 版本,FluidSynth 的命令处理器在接受 命令时,未对通道(channel)参数进行边界检查,就直接将提供的值写入所选的合成器通道。因此,超出范围的通道可能导致越界堆写入(out-of-bounds heap write),进而引发拒绝服务(DoS)或潜在的可执行代码攻击。 该问题在启用 TCP 服务器时可通过远程访问,例如通过 函数或 命令启动 TCP 服务;此外,也可通过向 FluidSynth

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1201 · Password Policy Discovery
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-58264

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FluidSynth: Heap-based buffer overrun
Source: CVE Program / CVE List V5
Vulnerability Description
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible code execution. The issue is remotely reachable when the TCP server is enabled through new_fluid_server() or fluidsynth -s, and it is locally reachable through malicious commands delivered to the FluidSynth shell on standard input. Applications that do not use the shell, command handler, or TCP server are not affected. This issue is fixed in version 2.5.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
FluidSynth fluidsynth >= 1.1.2, < 2.5.6 -

II. Public POCs for CVE-2026-58264

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-58264

登录查看更多情报信息。

Patches & Fixes for CVE-2026-58264 (2)

Other References for CVE-2026-58264 (2)

Same Patch Batch · FluidSynth · 2026-09-18 · 6 CVEs total

CVE-2026-61721 8.0 HIGH FluidSynth: Heap-based buffer overrun for DLS samples
CVE-2026-61714 7.8 HIGH FluidSynth: Heap Buffer Overflow in MIDI Player
CVE-2026-61723 6.8 MEDIUM FluidSynth: DLS ptbl Chunk Integer Overflow
CVE-2026-61722 6.8 MEDIUM FluidSynth: DLS Articulation Chunk Integer Overflow
CVE-2026-61720 6.2 MEDIUM FluidSynth: SF2 DMOD Chunk Unsigned Underflow

IV. Related Vulnerabilities

V. Comments for CVE-2026-58264

No comments yet


Leave a comment