Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-58264: FluidSynth can be crashed or hijacked via TCP

CVE-2026-58264 · published 3 days ago
Summary

Versions of FluidSynth from 1.1.2 through 2.5.6 let specially crafted commands write outside of memory, which can cause the program to stop working or let an attacker run code. The problem appears when the built‑in TCP server or command line shell is used. Upgrade to version 2.5.6 or later, or disable the TCP server and command interface if you do not need them.

What to do
  • Update debian fluidsynth to version 2.4.4+dfsg-1+deb13u3.
  • Update debian fluidsynth to version 2.5.6+dfsg-1.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian fluidsynth All versions
Debian:12 debian fluidsynth All versions
Debian:13 debian fluidsynth < 2.4.4+dfsg-1+deb13u3
Fix: upgrade to 2.4.4+dfsg-1+deb13u3
Debian:14 debian fluidsynth < 2.5.6+dfsg-1
Fix: upgrade to 2.5.6+dfsg-1
fluidsynth fluidsynth >= 1.1.2, < 2.5.6
Ubuntu:14.04:LTS canonical fluidsynth All versions
Original advisory text
FluidSynth: Heap-based buffer overrun
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth channel. An out-of-range channel can therefore cause an out-of-bounds heap write, leading to denial of service or possible code execution. The issue is remotely reachable when the TCP server is enabled through new_fluid_server() or fluidsynth -s, and it is locally reachable through malicious commands delivered to the FluidSynth shell on standard input. Applications that do not use the shell, command handler, or TCP server are not affected. This issue is fixed in version 2.5.6.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published18 Sep 2026
Updated21 Sep 2026
First seen24 Jul 2026
Track software like this
Free during beta