[Git][security-tracker-team/security-tracker][master] Add new fluidsynth issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 24 06:47:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8a47000f by Salvatore Bonaccorso at 2026-07-24T07:47:11+02:00
Add new fluidsynth issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,47 @@
+CVE-2026-58264 [heap-based buffer overrun in command handler]
+	- fluidsynth 2.5.6+dfsg-1
+	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-mqmq-w63q-cj94
+	NOTE: https://github.com/FluidSynth/fluidsynth/pull/1796
+	NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/8131539ad6c37a832bd67ee26791ef8e28259423 (v1.1.2)
+	NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/762a3bd39a431cd45abf3bbcce7286c87909d087 (v2.5.6)
+CVE-2026-61714 [heap-based buffer overflow in MIDI player]
+	- fluidsynth 2.5.6+dfsg-1
+	[bullseye] - fluidsynth <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6
+	NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/6c593180ce05f8bbbd07217456bc4376a4ab4505 (v2.2.4)
+	NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/772702e00cc6acc7c607efb40283e2269211effc (v2.5.6)
+CVE-2026-61721 [heap-based buffer overrun for DLS samples]
+	- fluidsynth 2.5.6+dfsg-1
+	[trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	[bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	[bullseye] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-59ph-rx8r-8p4j
+	NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
+	NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/2354c2a9acdb26de7cdcd37c903ee108f46c0a7d (v2.5.6)
+CVE-2026-61723 ]DLS ptbl chunk integer overflow]
+	- fluidsynth 2.5.6+dfsg-1
+	[trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	[bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	[bullseye] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-r4mc-v3p8-pv47
+	NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
+	NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/a2ab32b9c3b9f8845b7254adea73c211f6c5a24c (v2.5.6)
+CVE-2026-61722 [DLS articulation chunk integer overflow]
+	- fluidsynth 2.5.6+dfsg-1
+	[trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	[bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	[bullseye] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-hp72-35pr-6h6r
+	NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/c959f8d208bbad9e396dfb745285806b5a4c5a07 (v2.5.0)
+	NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/4d7084fca7c876f5d738498b4917a39faf603425 (v2.5.6)
+CVE-2026-61720 [SF2 DMOD chunk integer underflow]
+	- fluidsynth 2.5.6+dfsg-1
+	[trixie] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	[bookworm] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	[bullseye] - fluidsynth <not-affected> (Vulnerable code introduced later)
+	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-rmc4-c8hw-455w
+	NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/9c387006c2e09e32e0fdc35cdd4370b89edc969b (v2.5.0)
+	NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/096e1ff0d09ddcac83d94923440706f76f94bc44 (v2.5.6)
 CVE-2026-9729 (The Webpushr Push Notifications plugin for WordPress is vulnerable to  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-9713 (The Lumise Product Designer for WooCommerce plugin for WordPress is vu ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a47000fa9f9306c293a771cfce3f2005948768f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8a47000fa9f9306c293a771cfce3f2005948768f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/6671eb12/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list