No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 21 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sun, 20 Sep 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fluidsynth
Fluidsynth fluidsynth |
|
| Vendors & Products |
Fluidsynth
Fluidsynth fluidsynth |
Fri, 18 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.5.0 until 2.5.6, the SF2 parser computes the DMOD modulator count as chunk.size / SF_MOD_SIZE - 1 without rejecting chunks smaller than one record. A crafted SF2 file containing a zero-sized DMOD chunk makes the unsigned subtraction wrap to UINT_MAX, and the parser then attempts billions of SFMod allocations. This exhausts process memory and causes denial of service. No workaround is available. This issue is fixed in version 2.5.6. | |
| Title | FluidSynth: SF2 DMOD Chunk Unsigned Underflow | |
| Weaknesses | CWE-191 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-21T16:27:25.573Z
Reserved: 2026-07-10T18:51:13.920Z
Link: CVE-2026-61720
Updated: 2026-09-21T16:27:18.979Z
Status : Received
Published: 2026-09-18T20:17:18.420
Modified: 2026-09-21T17:17:36.827
Link: CVE-2026-61720
No data.
OpenCVE Enrichment
Updated: 2026-09-20T02:45:18Z