Skip to content

Use after free in fluidsynth

High
derselbst published GHSA-6fcq-pxhc-jxc9 Mar 31, 2021

Package

fluidsynth

Affected versions

<= 2.1.7

Patched versions

2.1.8

Description

Impact

A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file.

Patches

Upgrade to fluidsynth 2.1.8 or later

Workarounds

None

References

#808

Severity

High

CVE ID

CVE-2021-21417

Weaknesses

Credits