CVE-2021-21417: Use after free in fluidsynth
fluidsynth is a software synthesizer based on the SoundFont 2 specifications. A use after free violation was discovered in fluidsynth, that can be triggered when loading an invalid SoundFont file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-21417?
CVE-2021-21417 is a vulnerability in fluidsynth, a software synthesizer based on the SoundFont 2 specifications, that allows for a use after free violation when loading an invalid SoundFont file.
What is the severity of CVE-2021-21417?
CVE-2021-21417 has a severity rating of 5.5 (high).
Which software versions are affected by CVE-2021-21417?
Fluidsynth versions up to exclusive 2.1.8 and Debian Linux version 9.0 are affected by CVE-2021-21417.
How can the use after free violation be triggered in fluidsynth?
The use after free violation in fluidsynth can be triggered when loading an invalid SoundFont file.
How can I fix CVE-2021-21417?
To fix CVE-2021-21417, it is recommended to update to a fixed version of fluidsynth and Debian Linux, if available. Additionally, ensure that you only load valid SoundFont files.