buildroot ▾
›
2025.02.x ▾
›
component
›
fluidsynth
Component Overview
Vulnerability Overview
Name
fluidsynth
Version
2.4.3
Type
library
Description
-
Licenses
LGPL-2.1+
PURL
-
CPE
cpe:2.3:a:fluidsynth:fluidsynth:2.4.3:-:*:*:*:*:*:*
Other Versions
#
Project
Branch
Version
buildroot
master
2.4.7
Patches
#
#
Title
Author
Resolve
1
Fix a nullpointer dereference during legato mode (#1607)
"Tom M." <tom.mbrt@googlemail.com>
CVE-2025-56225
Vulnerabilities
#
Name
Analysis
Description
CVE-2025-56225
Patched
fluidsynth-2.4.6 and earlier versions is vulnerable to Null pointer dereference in fluid_synth_monopoly.c, that can be triggered when loading an invalid midi file.