rpm package
opensuse/fluidsynth&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/fluidsynth&distro=openSUSE%20Tumbleweed
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-58264 | Cri | 9.8 | < 2.5.6-1.1 | 2.5.6-1.1 | Sep 18, 2026 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth cha | |
| CVE-2025-56225 | Hig | 7.5 | < 2.5.2-2.1 | 2.5.2-2.1 | Jan 9, 2026 | fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file. | |
| CVE-2025-68617 | Hig | 7.0 | < 2.5.2-1.1 | 2.5.2-1.1 | Dec 23, 2025 | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS file can trigger a heap-based use-after-free. A concurrently running thread may be pending to unload a DLS file, leading t |
- affected < 2.5.6-1.1fixed 2.5.6-1.1
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 1.1.2 until 2.5.6, the FluidSynth command handler accepts a pitch_bend_range command whose channel argument is not bounds checked before the supplied value is written through the selected synth cha
- affected < 2.5.2-2.1fixed 2.5.2-2.1
fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.
- affected < 2.5.2-1.1fixed 2.5.2-1.1
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From versions 2.5.0 to before 2.5.2, a race condition during unloading of a DLS file can trigger a heap-based use-after-free. A concurrently running thread may be pending to unload a DLS file, leading t