CVE-2026-58264
Description
A flaw was found in FluidSynth. The pitch_bend_range command handler does not check that the channel argument is inside the synthesizer channel array before writing the supplied value, which is an out-of-bounds heap write. An attacker who can send commands to the FluidSynth shell can crash the process and could execute code. Remote attacks require the TCP server, which is disabled unless the application calls new_fluid_server() or the user starts fluidsynth with -s. Local attacks require malicious commands on standard input. Applications that do not use the shell, the command handler, or the TCP server are not affected.
Statement
Red Hat rates this issue Moderate. The CVE score of 9.8 describes attack against the FluidSynth TCP server. That server is disabled by default. Typical use of FluidSynth as a synthesizer library does not expose the vulnerable command handler.
Mitigation
Do not enable the FluidSynth TCP server: do not pass -s, and do not call
new_fluid_server(). Do not feed untrusted input to the FluidSynth shell.
Applications that only use the synthesizer API are not exposed to this
flaw. Where the shell or TCP server is required, upgrade to FluidSynth
2.5.6 or later.
Understanding the Weakness (CWE)
Integrity
Technical Impact: Modify Memory; Execute Unauthorized Code or Commands
Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.
Other
Technical Impact: Unexpected State
Subsequent write operations can produce undefined or unexpected results.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.