fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.
References
| Link | Resource |
|---|---|
| https://github.com/FluidSynth/fluidsynth/issues/1602 | Exploit Issue Tracking |
| https://github.com/FluidSynth/fluidsynth/pull/1607 | Issue Tracking |
| https://github.com/FluidSynth/fluidsynth/issues/1602 | Exploit Issue Tracking |
Configurations
History
No history.
Information
Published : 2026-01-09 16:16
Updated : 2026-01-23 02:13
NVD link : CVE-2025-56225
Mitre link : CVE-2025-56225
CVE.ORG link : CVE-2025-56225
JSON object : View
Products Affected
fluidsynth
- fluidsynth
CWE
CWE-476
NULL Pointer Dereference
