| Release | Version |
|---|---|
| bullseye | 2.1.7-1.1 |
| bookworm | 2.3.1-2 |
| trixie | 2.4.4+dfsg-1+deb13u2 |
| forky | 2.5.7+dfsg-1 |
| sid | 2.5.7+dfsg-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-61714 | fixed | vulnerable (no DSA, postponed) | vulnerable | fixed | fixed | heap-based buffer overflow in MIDI player |
| CVE-2026-58264 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable | fixed | fixed | heap-based buffer overrun in command handler |
| CVE-2025-56225 | vulnerable (no DSA, postponed) | vulnerable (no DSA) | fixed | fixed | fixed | fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer de ... |
| Bug | Description |
|---|---|
| CVE-2026-61723 | ]DLS ptbl chunk integer overflow] |
| CVE-2026-61722 | DLS articulation chunk integer overflow |
| CVE-2026-61721 | heap-based buffer overrun for DLS samples |
| CVE-2026-61720 | SF2 DMOD chunk integer underflow |
| CVE-2025-68617 | FluidSynth is a software synthesizer based on the SoundFont 2 specific ... |
| CVE-2021-21417 | fluidsynth is a software synthesizer based on the SoundFont 2 specific ... |
| DSA / DLA | Description |
|---|---|
| DLA-2697-1 | fluidsynth - security update |