FluidSynth 是一款基于 SoundFont 2 规范实现的软件合成器。在 2.2.4 至 2.5.6 版本中,若将配置项 设置为大于 16,MIDI 播放器在追踪活动通道时,会导致对 的索引超出其固定大小堆分配的范围。由此引发的越界读取和写入会触发未定义行为,可能影响数据的机密性、完整性或可用性。由于该不安全状态由通道数配置本身引起,因此无需特制的 MIDI 文件即可触发。将 保持默认值 16 可避免进入存在漏洞的代码路径。该问题已在 2.5.6 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FluidSynth | fluidsynth | >= 2.2.4, < 2.5.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58264 | 9.8 CRITICAL | FluidSynth: Heap-based buffer overrun |
| CVE-2026-61721 | 8.0 HIGH | FluidSynth: Heap-based buffer overrun for DLS samples |
| CVE-2026-61723 | 6.8 MEDIUM | FluidSynth: DLS ptbl Chunk Integer Overflow |
| CVE-2026-61722 | 6.8 MEDIUM | FluidSynth: DLS Articulation Chunk Integer Overflow |
| CVE-2026-61720 | 6.2 MEDIUM | FluidSynth: SF2 DMOD Chunk Unsigned Underflow |
No comments yet