PT-2026-56860 · Unknown · Fluidsynth

CVE-2026-58264

·

Published

2026-07-08

·

Updated

2026-07-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FluidSynth versions prior to 2.5.6-1.1
Description A heap-based buffer overrun exists in the command handler. This occurs when a pitch bend range command is sent with an out-of-bounds channel argument, causing the system to attempt to write the value argument into heap memory. If the command handler is exposed through the TCP server, created via new fluid server() or the fluidsynth -s command, a remote attacker could manipulate heap memory to cause a denial of service or achieve remote code execution.
Recommendations Update to version 2.5.6-1.1 or newer.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-58264
ECHO-C5C2-10B5-9D2D
OESA-2026-2959
OESA-2026-2960
OESA-2026-2961
OESA-2026-3081
OPENSUSE-SU-2026:11211-1

Affected Products

Fluidsynth