Bug 2538395 (CVE-2026-61714)

Summary: CVE-2026-61714 FluidSynth: FluidSynth: Heap Buffer Overflow via MIDI channel configuration
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in FluidSynth, a software synthesizer. When the `synth.midi-channels` configuration is set above 16, the MIDI player can write beyond the allocated memory for tracking active channels. This heap buffer overflow can lead to out-of-bounds memory access, potentially compromising the confidentiality, integrity, or availability of the system. This vulnerability is triggered by the configuration itself and does not require a specially crafted MIDI file.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2539215    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-22 18:26:14 UTC
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. From 2.2.4 until 2.5.6, configuring synth.midi-channels above 16 allows the MIDI player to index _fluid_player_t::channel_isplaying outside its fixed-size heap allocation while tracking active channels. The resulting out-of-bounds reads and writes invoke undefined behavior and may compromise confidentiality, integrity, or availability. No crafted MIDI file is required because the unsafe condition is created by the channel-count configuration itself. Keeping synth.midi-channels at its default value of 16 avoids the vulnerable path. This issue is fixed in version 2.5.6.