PT-2026-56860 · Unknown · Fluidsynth
CVE-2026-58264
·
Published
2026-07-08
·
Updated
2026-07-27
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FluidSynth versions prior to 2.5.6-1.1
Description
A heap-based buffer overrun exists in the command handler. This occurs when a
pitch bend range command is sent with an out-of-bounds channel argument, causing the system to attempt to write the value argument into heap memory. If the command handler is exposed through the TCP server, created via new fluid server() or the fluidsynth -s command, a remote attacker could manipulate heap memory to cause a denial of service or achieve remote code execution.Recommendations
Update to version 2.5.6-1.1 or newer.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fluidsynth