
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-61714 is a heap-based buffer overflow vulnerability in FluidSynth's MIDI player component. When the synthesizer is configured with synth.midi-channels set to a value greater than 16, an out-of-bounds memory access is performed on the _fluid_player_t::channel_isplaying array in heap memory, invoking undefined behavior. The vulnerability affects FluidSynth versions 2.2.4 through 2.5.5 (inclusive), and was patched in version 2.5.6. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory).
The root cause is classified under CWE-122 (Heap-based Buffer Overflow), CWE-125 (Out-of-bounds Read), and CWE-787 (Out-of-bounds Write). The flaw was introduced in commit 6c59318 and stems from the MIDI player not properly bounding array accesses to _fluid_player_t::channel_isplaying when the number of MIDI channels exceeds the default value of 16. Exploitation requires local access and user interaction (e.g., opening a MIDI file), but notably does not require a specially crafted MIDI file — any MIDI playback while the misconfiguration is active can trigger the overflow. The fix was applied in commit 772702e (GitHub Advisory).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected system. An attacker who can influence a user to play MIDI content while FluidSynth is misconfigured could achieve arbitrary code execution in the context of the application, potentially leading to data disclosure, data corruption, or application crash. The scope is limited to the affected component (unchanged scope), but the combination of all three high-severity CIA impacts makes this a significant local exploitation risk (GitHub Advisory).
The CVE status is currently listed as "Reserved" with limited public exploit details available. The vulnerability requires local access and user interaction, reducing its remote exploitability. No public proof-of-concept exploit code, in-the-wild exploitation, or threat actor attribution has been reported at this time. The vulnerability was detected by Nessus plugin 329708, indicating scanner-level detection capability is available (Tenable, OSV).
synth.midi-channels setting has been configured to a value greater than 16 (non-default)._fluid_player_t::channel_isplaying beyond its allocated bounds due to the elevated channel count, causing a heap buffer overflow.malloc corruption errors).synth.midi-channels set to a value greater than 16, indicating the precondition for exploitation is met.Update FluidSynth to version 2.5.6 or later, which contains the fix applied in commit 772702e. Ubuntu users should apply the fixed package versions provided via Ubuntu security updates. As an immediate workaround, keep synth.midi-channels at its default value of 16 — this prevents the out-of-bounds array access from occurring. Organizations should audit FluidSynth configurations across their environments to identify any non-default channel settings (GitHub Advisory, OSV).
The vulnerability was discovered by security researcher TristanInSec and remediated by FluidSynth maintainer derselbst, who published the GitHub Security Advisory on July 4, 2026. No significant broader media coverage or notable community commentary beyond the official advisory has been identified at this time (GitHub Advisory).
Fix availability across major Linux distributions and their releases.
bookworm
fluidsynth
sid
fluidsynth: 2.5.6+dfsg-1
trixie
fluidsynth: 2.4.4+dfsg-1+deb13u3
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."