Bug#1146368: trixie-pu: package fluidsynth/2.4.4+dfsg-1+deb13u3

Moritz Muehlenhoff <[email protected]>
Newsgroups gmane.linux.debian.devel.release
Message-ID <178820921548.15317.9040991832396989376.reportbug__46707.2511486307$1788209381$gmane$org@soju.westfalen.local>
Package: release.debian.org
Severity: normal
Tags: trixie
X-Debbugs-Cc: [email protected], [email protected]
Control: affects -1 + src:fluidsynth
User: [email protected]
Usertags: pu

Fixes two low severity security issues, all tests were fine
and tests in debusine look good. Debdiff below.

Cheers,
        Moritz

diff -Nru fluidsynth-2.4.4+dfsg/debian/changelog fluidsynth-2.4.4+dfsg/debian/changelog
--- fluidsynth-2.4.4+dfsg/debian/changelog	2026-03-04 20:50:29.000000000 +0100
+++ fluidsynth-2.4.4+dfsg/debian/changelog	2026-08-30 19:13:05.000000000 +0200
@@ -1,3 +1,10 @@
+fluidsynth (2.4.4+dfsg-1+deb13u3) trixie; urgency=medium
+
+  * CVE-2026-58264
+  * CVE-2026-61714
+
+ -- Moritz Mühlenhoff <[email protected]>  Sun, 30 Aug 2026 19:13:05 +0200
+
 fluidsynth (2.4.4+dfsg-1+deb13u2) trixie; urgency=medium
 
   * CVE-2025-56225
diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch
--- fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch	1970-01-01 01:00:00.000000000 +0100
+++ fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch	2026-08-28 12:11:54.000000000 +0200
@@ -0,0 +1,17 @@
+From 762a3bd39a431cd45abf3bbcce7286c87909d087 Mon Sep 17 00:00:00 2001
+From: derselbst <[email protected]>
+Date: Fri, 19 Jun 2026 20:11:54 +0200
+Subject: [PATCH] Fix a heap-based buffer overrun in pitch_bend_range command
+
+--- fluidsynth-2.4.4+dfsg.orig/src/bindings/fluid_cmd.c
++++ fluidsynth-2.4.4+dfsg/src/bindings/fluid_cmd.c
+@@ -795,8 +795,7 @@ fluid_handle_pitch_bend_range(void *data
+ 
+     channum = atoi(av[0]);
+     value = atoi(av[1]);
+-    fluid_channel_set_pitch_wheel_sensitivity(handler->synth->channel[channum], value);
+-    return FLUID_OK;
++    return fluid_synth_pitch_wheel_sens(handler->synth, channum, value);
+ }
+ 
+ int
diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch
--- fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch	1970-01-01 01:00:00.000000000 +0100
+++ fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch	2026-08-28 12:12:45.000000000 +0200
@@ -0,0 +1,39 @@
+From 772702e00cc6acc7c607efb40283e2269211effc Mon Sep 17 00:00:00 2001
+From: derselbst <[email protected]>
+Date: Sat, 27 Jun 2026 08:51:10 +0200
+Subject: [PATCH] Fix heap buffer overflow in MIDI player GHSA-976m-35rw-h3m6
+
+--- fluidsynth-2.4.4+dfsg.orig/src/midi/fluid_midi.c
++++ fluidsynth-2.4.4+dfsg/src/midi/fluid_midi.c
+@@ -1617,10 +1617,11 @@ fluid_track_send_events(fluid_track_t *t
+         {
+             if(player->playback_callback)
+             {
++                int *chan_is_playing = &player->channel_isplaying[event->channel % MAX_NUMBER_OF_CHANNELS];
+                 player->playback_callback(player->playback_userdata, event);
+-                if(event->type == NOTE_ON && event->param2 != 0 && !player->channel_isplaying[event->channel])
++                if(event->type == NOTE_ON && event->param2 != 0 && !*chan_is_playing)
+                 {
+-                    player->channel_isplaying[event->channel] = TRUE;
++                    *chan_is_playing = TRUE;
+                 }
+             }
+         }
+@@ -2138,7 +2139,7 @@ fluid_player_callback(void *data, unsign
+     {
+         if(fluid_atomic_int_get(&player->stopping))
+         {
+-            for(i = 0; i < synth->midi_channels; i++)
++            for(i = 0; i < MAX_NUMBER_OF_CHANNELS; i++)
+             {
+                 if(player->channel_isplaying[i])
+                 {
+@@ -2186,7 +2187,7 @@ fluid_player_callback(void *data, unsign
+         seek_ticks = fluid_atomic_int_get(&player->seek_ticks);
+         if(seek_ticks >= 0)
+         {
+-            for(i = 0; i < synth->midi_channels; i++)
++            for(i = 0; i < MAX_NUMBER_OF_CHANNELS; i++)
+             {
+                 if(player->channel_isplaying[i])
+                 {
diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/series fluidsynth-2.4.4+dfsg/debian/patches/series
--- fluidsynth-2.4.4+dfsg/debian/patches/series	2026-03-04 20:50:16.000000000 +0100
+++ fluidsynth-2.4.4+dfsg/debian/patches/series	2026-08-28 12:12:34.000000000 +0200
@@ -1 +1,3 @@
 CVE-2025-56225.patch
+CVE-2026-58264.patch
+CVE-2026-61714.patch
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.