Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + src:fluidsynth
User: [email protected]
Usertags: pu
Fixes two low severity security issues, all tests were fine
and tests in debusine look good. Debdiff below.
Cheers,
Moritz
diff -Nru fluidsynth-2.4.4+dfsg/debian/changelog
fluidsynth-2.4.4+dfsg/debian/changelog
--- fluidsynth-2.4.4+dfsg/debian/changelog 2026-03-04 20:50:29.000000000
+0100
+++ fluidsynth-2.4.4+dfsg/debian/changelog 2026-08-30 19:13:05.000000000
+0200
@@ -1,3 +1,10 @@
+fluidsynth (2.4.4+dfsg-1+deb13u3) trixie; urgency=medium
+
+ * CVE-2026-58264
+ * CVE-2026-61714
+
+ -- Moritz Mühlenhoff <[email protected]> Sun, 30 Aug 2026 19:13:05 +0200
+
fluidsynth (2.4.4+dfsg-1+deb13u2) trixie; urgency=medium
* CVE-2025-56225
diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch
fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch
--- fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch 1970-01-01
01:00:00.000000000 +0100
+++ fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch 2026-08-28
12:11:54.000000000 +0200
@@ -0,0 +1,17 @@
+From 762a3bd39a431cd45abf3bbcce7286c87909d087 Mon Sep 17 00:00:00 2001
+From: derselbst <[email protected]>
+Date: Fri, 19 Jun 2026 20:11:54 +0200
+Subject: [PATCH] Fix a heap-based buffer overrun in pitch_bend_range command
+
+--- fluidsynth-2.4.4+dfsg.orig/src/bindings/fluid_cmd.c
++++ fluidsynth-2.4.4+dfsg/src/bindings/fluid_cmd.c
+@@ -795,8 +795,7 @@ fluid_handle_pitch_bend_range(void *data
+
+ channum = atoi(av[0]);
+ value = atoi(av[1]);
+-
fluid_channel_set_pitch_wheel_sensitivity(handler->synth->channel[channum],
value);
+- return FLUID_OK;
++ return fluid_synth_pitch_wheel_sens(handler->synth, channum, value);
+ }
+
+ int
diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch
fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch
--- fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch 1970-01-01
01:00:00.000000000 +0100
+++ fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch 2026-08-28
12:12:45.000000000 +0200
@@ -0,0 +1,39 @@
+From 772702e00cc6acc7c607efb40283e2269211effc Mon Sep 17 00:00:00 2001
+From: derselbst <[email protected]>
+Date: Sat, 27 Jun 2026 08:51:10 +0200
+Subject: [PATCH] Fix heap buffer overflow in MIDI player GHSA-976m-35rw-h3m6
+
+--- fluidsynth-2.4.4+dfsg.orig/src/midi/fluid_midi.c
++++ fluidsynth-2.4.4+dfsg/src/midi/fluid_midi.c
+@@ -1617,10 +1617,11 @@ fluid_track_send_events(fluid_track_t *t
+ {
+ if(player->playback_callback)
+ {
++ int *chan_is_playing =
&player->channel_isplaying[event->channel % MAX_NUMBER_OF_CHANNELS];
+ player->playback_callback(player->playback_userdata, event);
+- if(event->type == NOTE_ON && event->param2 != 0 &&
!player->channel_isplaying[event->channel])
++ if(event->type == NOTE_ON && event->param2 != 0 &&
!*chan_is_playing)
+ {
+- player->channel_isplaying[event->channel] = TRUE;
++ *chan_is_playing = TRUE;
+ }
+ }
+ }
+@@ -2138,7 +2139,7 @@ fluid_player_callback(void *data, unsign
+ {
+ if(fluid_atomic_int_get(&player->stopping))
+ {
+- for(i = 0; i < synth->midi_channels; i++)
++ for(i = 0; i < MAX_NUMBER_OF_CHANNELS; i++)
+ {
+ if(player->channel_isplaying[i])
+ {
+@@ -2186,7 +2187,7 @@ fluid_player_callback(void *data, unsign
+ seek_ticks = fluid_atomic_int_get(&player->seek_ticks);
+ if(seek_ticks >= 0)
+ {
+- for(i = 0; i < synth->midi_channels; i++)
++ for(i = 0; i < MAX_NUMBER_OF_CHANNELS; i++)
+ {
+ if(player->channel_isplaying[i])
+ {
diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/series
fluidsynth-2.4.4+dfsg/debian/patches/series
--- fluidsynth-2.4.4+dfsg/debian/patches/series 2026-03-04 20:50:16.000000000
+0100
+++ fluidsynth-2.4.4+dfsg/debian/patches/series 2026-08-28 12:12:34.000000000
+0200
@@ -1 +1,3 @@
CVE-2025-56225.patch
+CVE-2026-58264.patch
+CVE-2026-61714.patch