[Git][security-tracker-team/security-tracker][master] Add new fluidsynth issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 24 06:47:47 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8a47000f by Salvatore Bonaccorso at 2026-07-24T07:47:11+02:00
Add new fluidsynth issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,47 @@
+CVE-2026-58264 [heap-based buffer overrun in command handler]
+ - fluidsynth 2.5.6+dfsg-1
+ NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-mqmq-w63q-cj94
+ NOTE: https://github.com/FluidSynth/fluidsynth/pull/1796
+ NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/8131539ad6c37a832bd67ee26791ef8e28259423 (v1.1.2)
+ NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/762a3bd39a431cd45abf3bbcce7286c87909d087 (v2.5.6)
+CVE-2026-61714 [heap-based buffer overflow in MIDI player]
+ - fluidsynth 2.5.6+dfsg-1
+ [bullseye] - fluidsynth <not-affected> (Vulnerable code not present)
+ NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6
+ NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/6c593180ce05f8bbbd07217456bc4376a4ab4505 (v2.2.4)
+ NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/772702e00cc6acc7c607efb40283e2269211effc (v2.5.6)
+CVE-2026-61721 [heap-based buffer overrun for DLS samples]
+ - fluidsynth 2.5.6+dfsg-1
+ [trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ [bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ [bullseye] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-59ph-rx8r-8p4j
+ NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
+ NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/2354c2a9acdb26de7cdcd37c903ee108f46c0a7d (v2.5.6)
+CVE-2026-61723 ]DLS ptbl chunk integer overflow]
+ - fluidsynth 2.5.6+dfsg-1
+ [trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ [bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ [bullseye] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-r4mc-v3p8-pv47
+ NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
+ NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/a2ab32b9c3b9f8845b7254adea73c211f6c5a24c (v2.5.6)
+CVE-2026-61722 [DLS articulation chunk integer overflow]
+ - fluidsynth 2.5.6+dfsg-1
+ [trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ [bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ [bullseye] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-hp72-35pr-6h6r
+ NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
+ NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/4d7084fca7c876f5d738498b4917a39faf603425 (v2.5.6)
+CVE-2026-61720 [SF2 DMOD chunk integer underflow]
+ - fluidsynth 2.5.6+dfsg-1
+ [trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ [bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ [bullseye] - fluidsynth <not-affected> (Vulnerable code introduced later)
+ NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-rmc4-c8hw-455w
+ NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/9c387006c2e09e32e0fdc35cdd4370b89edc969b (v2.5.0)
+ NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/096e1ff0d09ddcac83d94923440706f76f94bc44 (v2.5.6)
CVE-2026-9729 (The Webpushr Push Notifications plugin for WordPress is vulnerable to ...)
NOT-FOR-US: WordPress plugin
CVE-2026-9713 (The Lumise Product Designer for WooCommerce plugin for WordPress is vu ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a47000fa9f9306c293a771cfce3f2005948768f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a47000fa9f9306c293a771cfce3f2005948768f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/6671eb12/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list