CVE-2026-61722 Overview
FluidSynth is a software synthesizer based on the SoundFont 2 specifications. CVE-2026-61722 is an integer overflow vulnerability [CWE-190] in the native Downloadable Sounds (DLS) parser affecting versions 2.5.0 through 2.5.5. The parser validates articulation chunks using the unsigned expression cbsize + connblocks * 12 without confirming the arithmetic fits in 32 bits. A crafted DLS file supplying a large connblocks value wraps the expression, bypasses the chunk-size check, and forces the parser into approximately one billion 12-byte iterations beyond the chunk boundary. The issue is fixed in version 2.5.6.
Critical Impact
A local attacker can trigger denial of service and invalid memory reads by supplying a malicious DLS file to any application built with enable-native-dls enabled.
Affected Products
- FluidSynth 2.5.0
- FluidSynth 2.5.1 through 2.5.5
- Applications embedding FluidSynth built with the CMake option enable-native-dls set to ON
Discovery Timeline
- 2026-09-18 - CVE-2026-61722 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-61722
Vulnerability Analysis
The vulnerability resides in the native DLS parser located in src/sfloader/fluid_dls.cpp. When FluidSynth processes an articulation chunk, the parser calculates the expected data size by adding cbsize to connblocks * 12. Both operands are unsigned 32-bit integers, and neither the multiplication nor the subsequent addition is checked for overflow before comparison against the chunk boundary.
An attacker supplying a sufficiently large connblocks value causes connblocks * 12 to wrap around zero. The wrapped result plus cbsize produces a value small enough to pass the chunk-size validation. The parser then proceeds to iterate over the original, unwrapped connblocks count, reading approximately one billion 12-byte structures past the end of the legitimate chunk data. The excessive iteration consumes CPU time and triggers out-of-bounds reads that terminate the process.
Root Cause
The root cause is missing overflow validation on unsigned 32-bit arithmetic. The parser trusts attacker-controlled length fields inside RIFF subchunks without enforcing an upper bound on connblocks prior to multiplication. Related code paths in the same file share the pattern, including poolcue handling where the bound (std::numeric_limits<uint32_t>::max() - cbsize) / 4 must also use unsigned arithmetic to avoid signed-conversion pitfalls.
Attack Vector
Exploitation requires local delivery of a crafted DLS file to a FluidSynth-based application. The attacker persuades a user or automated pipeline to load the malicious file, at which point the parser performs the runaway loop and crashes. No authentication or user interaction beyond opening the file is required. Builds compiled with enable-native-dls=OFF are not exposed.
// Patch excerpt from src/sfloader/fluid_dls.cpp
// Fix DLS articulation chunk int overflow GHSA-hp72-35pr-6h6r
// subchunk.size is uint32 and can be at max 0xFFFF'FFFF, therefore the max value of cues will be 0x3FFF'FFFF, as bigger
// values would require an uint64 chunksize, contrary to the RIFF spec. Catch possible overflow here.
- if(cues > (std::numeric_limits<uint32_t>::max() - cbsize) / 4)
+ if(cues > (std::numeric_limits<uint32_t>::max() - cbsize) / 4u)
{
throw std::runtime_error{ "Too many poolcue records are contained in the ptbl chunk." };
}
Source: GitHub Commit 4d7084f
Detection Methods for CVE-2026-61722
Indicators of Compromise
- FluidSynth or embedding applications terminating unexpectedly shortly after loading a .dls file.
- Sustained single-core CPU saturation by a FluidSynth process during DLS load, followed by a crash or segmentation fault.
- Crash reports referencing symbols in fluid_dls.cpp or the DLS articulation parsing path.
Detection Strategies
- Inventory installations of FluidSynth and identify builds compiled with enable-native-dls=ON at versions earlier than 2.5.6.
- Inspect DLS files at ingestion for RIFF artl/art2 subchunks declaring implausibly large connblocks counts.
- Monitor process telemetry for FluidSynth crashes correlated with file open events sourced from untrusted paths.
Monitoring Recommendations
- Enable audit logging for user-mode crashes on hosts running audio processing pipelines that consume DLS content.
- Track file provenance for .dls assets loaded by services and reject files originating from untrusted sources.
- Alert on repeated short-lived FluidSynth process terminations, which may indicate probing for the overflow condition.
How to Mitigate CVE-2026-61722
Immediate Actions Required
- Upgrade FluidSynth to version 2.5.6 or later on all affected hosts.
- Audit downstream applications that bundle FluidSynth and confirm they ship the patched release.
- Restrict DLS file loading to trusted, validated sources until the upgrade is completed.
Patch Information
The fix is contained in FluidSynth commit 4d7084f and released in version 2.5.6. The patch enforces unsigned arithmetic when validating chunk lengths and rejects DLS inputs whose declared record counts would overflow the 32-bit calculation. Details are published in GitHub Security Advisory GHSA-hp72-35pr-6h6r and the GitHub Release v2.5.6 notes.
Workarounds
- Rebuild FluidSynth from source with the CMake option -Denable-native-dls=OFF to disable the vulnerable parser entirely.
- Block or quarantine untrusted .dls files at the file gateway or endpoint level.
- Sandbox FluidSynth-based services so a crash does not affect other workloads on the host.
# Rebuild FluidSynth without the native DLS parser
cmake -Denable-native-dls=OFF -B build -S .
cmake --build build
cmake --install build
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
