Skip to main content
Vulnerability Database/CVE-2026-61723

CVE-2026-61723: FluidSynth DLS Parser DOS Vulnerability

CVE-2026-61723 is a denial of service vulnerability in FluidSynth's native DLS parser that allows crafted files to trigger excessive memory allocation. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-61723 Overview

CVE-2026-61723 is an integer overflow vulnerability [CWE-190] in FluidSynth, an open-source software synthesizer based on the SoundFont 2 specifications. The flaw exists in the native Downloadable Sounds (DLS) parser in versions 2.5.0 through 2.5.5. A crafted DLS file can supply a cues value that overflows the unsigned expression cues * 4 + cbsize, bypassing the chunk-size validation check. The parser then attempts to allocate approximately four gigabytes of memory and read billions of entries past the chunk boundary. Builds compiled with enable-native-dls set to OFF are not affected. The issue is patched in version 2.5.6.

Critical Impact

A local attacker can supply a malicious DLS file to trigger excessive memory allocation and out-of-bounds reads, resulting in denial of service against applications that embed FluidSynth's native DLS parser.

Affected Products

  • FluidSynth 2.5.0 through 2.5.5 with enable-native-dls enabled
  • Applications embedding vulnerable FluidSynth builds for DLS file processing
  • Downstream distributions packaging FluidSynth 2.5.0–2.5.5

Discovery Timeline

  • 2026-09-18 - CVE-2026-61723 published to NVD
  • 2026-09-24 - Last updated in NVD database

Technical Details for CVE-2026-61723

Vulnerability Analysis

The vulnerability resides in the native DLS parser located in src/sfloader/fluid_dls.cpp. When processing the ptbl (pool table) chunk of a DLS file, the parser reads a 32-bit unsigned cues value that represents the number of pool cue records. It then validates the chunk size using the expression cues * 4 + cbsize and compares the result against subchunk.size. Because both the multiplication and addition are performed in 32-bit unsigned arithmetic, a large cues value causes the expression to wrap around modulo 2^32 and match the reported chunk size. The parser subsequently invokes poolcues.resize(cues), requesting roughly four gigabytes of memory, and iterates through billions of entries beyond the actual chunk boundary. The result is excessive memory pressure and invalid reads that terminate the host process.

Root Cause

The root cause is missing bounds validation on an arithmetic expression involving attacker-controlled input. The DLS specification permits cues up to 0x3FFFFFFF before requiring a 64-bit chunk size, but the original code did not enforce this upper bound before computing cues * 4 + cbsize.

Attack Vector

Exploitation requires the victim to open or load a crafted DLS file with an application that links against a vulnerable FluidSynth build. The attack vector is local, no privileges are required, and no user interaction beyond opening the file is needed to trigger the allocation and read failures.

cpp
                uint32_t cues; // sample count
                READ32(this, cues);

+               // subchunk.size is uint32 and can be at max 0xFFFF'FFFF, therefore the max value of cues will be 0x3FFF'FFFF, as bigger
+               // values would require an uint64 chunksize, contrary to the RIFF spec. Catch possible overflow here.
+               if(cues > (std::numeric_limits<uint32_t>::max() - cbsize) / 4)
+               {
+                   throw std::runtime_error{ "Too many poolcue records are contained in the ptbl chunk." };
+               }
+
                if(cues * 4 + cbsize != subchunk.size)
                {
                    throw std::runtime_error{ "DLS ptbl chunk has corrupted size" };

Source: FluidSynth commit a2ab32b — the patch adds an explicit overflow check before the existing chunk-size comparison, rejecting cues values that would wrap the 32-bit expression.

Detection Methods for CVE-2026-61723

Indicators of Compromise

  • Process crashes or terminations in applications that recently loaded a .dls file
  • Sudden memory allocation spikes of approximately four gigabytes originating from processes linked against libfluidsynth
  • Out-of-memory (OOM) killer events targeting audio applications or media processing pipelines
  • DLS files with abnormally large cues field values in the ptbl subchunk

Detection Strategies

  • Inventory installed FluidSynth binaries and libraries and compare versions against 2.5.6 to identify vulnerable instances
  • Inspect build flags of packaged FluidSynth binaries to determine whether enable-native-dls was set at compile time
  • Statically scan DLS files handled by media pipelines for oversized ptbl chunk header values

Monitoring Recommendations

  • Monitor process telemetry for abnormal allocation sizes and abrupt terminations tied to audio synthesis workloads
  • Alert on repeated crashes of processes that consume user-supplied DLS or SoundFont files
  • Correlate file-open events for .dls files with subsequent memory-exhaustion signals on the same host

How to Mitigate CVE-2026-61723

Immediate Actions Required

  • Upgrade FluidSynth to version 2.5.6 or later on all systems and rebuild dependent applications against the patched library
  • Audit third-party software that bundles FluidSynth and apply vendor updates as they become available
  • Restrict processing of DLS files sourced from untrusted origins until patched versions are deployed

Patch Information

The fix is available in FluidSynth release v2.5.6. The corrective commit is documented in the upstream GitHub Security Advisory GHSA-r4mc-v3p8-pv47 and applied in commit a2ab32b, which adds an explicit overflow guard before the ptbl chunk size comparison.

Workarounds

  • Rebuild FluidSynth with enable-native-dls set to OFF to remove the vulnerable code path entirely
  • Block or filter DLS files at ingestion points in media processing workflows until patches are deployed
  • Run applications that parse DLS files under strict resource limits to contain memory exhaustion impact
bash
# Rebuild FluidSynth without the native DLS parser to eliminate exposure
cmake -Denable-native-dls=OFF ..
make && sudo make install

# Verify the installed version is 2.5.6 or later
fluidsynth --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.