Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61721— FluidSynth: Heap-based buffer overrun for DLS samples

Quick assessment

Affected
FluidSynth fluidsynth
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FluidSynth 是一个基于 SoundFont 2 规范的软件合成器。在版本 2.5.0 至 2.5.6 中,原生 DLS 加载器会将由文件控制的 和 值直接赋值给样本,而未调用 或 进行验证或清理。经过精心构造的 DLS 文件可以将样本循环点设置到样本缓冲区之外,从而在音频渲染过程中触发越界读取,导致未定义行为、潜在的信息泄露以及服务拒绝(DoS)。使用 CMake 选项 设置为 OFF 编译的二进制文件不会暴露该受影响的解析器。该问题已在版本 2.5.6 中修复。

CVSS 8.0 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61721

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FluidSynth: Heap-based buffer overrun for DLS samples
Source: CVE Program / CVE List V5
Vulnerability Description
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the native DLS loader assigns file-controlled wsmp.loop_start and wsmp.loop_length values to samples without calling fluid_sample_validate() or fluid_sample_sanitize_loop(). A crafted DLS file can place sample loop points beyond the sample buffer, causing out-of-bounds reads during audio rendering, undefined behavior, possible memory disclosure, and denial of service. Builds compiled with the CMake option enable-native-dls set to OFF do not expose the affected parser. This issue is fixed in version 2.5.6.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
FluidSynth fluidsynth >= 2.5.0, < 2.5.6 -

II. Public POCs for CVE-2026-61721

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61721

登录查看更多情报信息。

Patches & Fixes for CVE-2026-61721 (1)

Other References for CVE-2026-61721 (2)

Same Patch Batch · FluidSynth · 2026-09-18 · 6 CVEs total

CVE-2026-58264 9.8 CRITICAL FluidSynth: Heap-based buffer overrun
CVE-2026-61714 7.8 HIGH FluidSynth: Heap Buffer Overflow in MIDI Player
CVE-2026-61723 6.8 MEDIUM FluidSynth: DLS ptbl Chunk Integer Overflow
CVE-2026-61722 6.8 MEDIUM FluidSynth: DLS Articulation Chunk Integer Overflow
CVE-2026-61720 6.2 MEDIUM FluidSynth: SF2 DMOD Chunk Unsigned Underflow

IV. Related Vulnerabilities

V. Comments for CVE-2026-61721

No comments yet


Leave a comment