CVE-2026-58264

Description

A flaw was found in FluidSynth. The pitch_bend_range command handler does not check that the channel argument is inside the synthesizer channel array before writing the supplied value, which is an out-of-bounds heap write. An attacker who can send commands to the FluidSynth shell can crash the process and could execute code. Remote attacks require the TCP server, which is disabled unless the application calls new_fluid_server() or the user starts fluidsynth with -s. Local attacks require malicious commands on standard input. Applications that do not use the shell, the command handler, or the TCP server are not affected.

Statement

Red Hat rates this issue Moderate. The CVE score of 9.8 describes attack against the FluidSynth TCP server. That server is disabled by default. Typical use of FluidSynth as a synthesizer library does not expose the vulnerable command handler.

Mitigation

Do not enable the FluidSynth TCP server: do not pass -s, and do not call
new_fluid_server(). Do not feed untrusted input to the FluidSynth shell.
Applications that only use the synthesizer API are not exposed to this
flaw. Where the shell or TCP server is required, upgrade to FluidSynth
2.5.6 or later.

Understanding the Weakness (CWE)

Integrity

Technical Impact: Modify Memory; Execute Unauthorized Code or Commands

Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.

Availability

Technical Impact: DoS: Crash, Exit, or Restart

Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.

Other

Technical Impact: Unexpected State

Subsequent write operations can produce undefined or unexpected results.

Frequently Asked Questions

Want to get errata notifications? Sign up here.