Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-58264: FluidSynth can be crashed or hijacked via TCP
CVE-2026-58264 · published 3 days ago
Summary
Versions of FluidSynth from 1.1.2 through 2.5.6 let specially crafted commands write outside of memory, which can cause the program to stop working or let an attacker run code. The problem appears when the built‑in TCP server or command line shell is used. Upgrade to version 2.5.6 or later, or disable the TCP server and command interface if you do not need them.
What to do
- Update debian fluidsynth to version 2.4.4+dfsg-1+deb13u3.
- Update debian fluidsynth to version 2.5.6+dfsg-1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | fluidsynth | All versions |
| Debian:12 | debian | fluidsynth | All versions |
| Debian:13 | debian | fluidsynth |
< 2.4.4+dfsg-1+deb13u3 Fix: upgrade to 2.4.4+dfsg-1+deb13u3
|
| Debian:14 | debian | fluidsynth |
< 2.5.6+dfsg-1 Fix: upgrade to 2.5.6+dfsg-1
|
| – | fluidsynth | fluidsynth | >= 1.1.2, < 2.5.6 |
| Ubuntu:14.04:LTS | canonical | fluidsynth | All versions |
Original advisory text
FluidSynth: Heap-based buffer overrun
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible code execution. The issue is remotely reachable when the TCP server is enabled through new_fluid_server() or fluidsynth -s, and it is locally reachable through malicious commands delivered to the FluidSynth shell on standard input. Applications that do not use the shell, command handler, or TCP server are not affected. This issue is fixed in version 2.5.6.
References
- https://security-tracker.debian.org/tracker/CVE-2026-58264 Vendor Advisory
- https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-mqmq-w63q-cj94
- https://github.com/FluidSynth/fluidsynth/pull/1796
- https://github.com/FluidSynth/fluidsynth/commit/762a3bd39a431cd45abf3bbcce7286c8...
- https://github.com/FluidSynth/fluidsynth/releases/tag/v2.5.6
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/58xxx/CVE-2026-58264... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-58264 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-58264 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-58264 Third Party Advisory
Severity
9.8
Critical
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published18 Sep 2026
Updated21 Sep 2026
First seen24 Jul 2026
Sources
DEBIAN-CVE-2026-58264 · OSV
CVE-2026-58264 · NVD
CVE-2026-58264 · MITRE
CVE-2026-58264 · OSV
GHSA-mqmq-w63q-cj94 · GHSA
UBUNTU-CVE-2026-58264 · OSV
Track software like this
Free during beta