Bug#1146368: trixie-pu: package fluidsynth/2.4.4+dfsg-1+deb13u3
Moritz Muehlenhoff <[email protected]>
| Newsgroups | gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <178820921548.15317.9040991832396989376.reportbug__46707.2511486307$1788209381$gmane$org@soju.westfalen.local> |
Package: release.debian.org Severity: normal Tags: trixie X-Debbugs-Cc: [email protected], [email protected] Control: affects -1 + src:fluidsynth User: [email protected] Usertags: pu Fixes two low severity security issues, all tests were fine and tests in debusine look good. Debdiff below. Cheers, Moritz diff -Nru fluidsynth-2.4.4+dfsg/debian/changelog fluidsynth-2.4.4+dfsg/debian/changelog --- fluidsynth-2.4.4+dfsg/debian/changelog 2026-03-04 20:50:29.000000000 +0100 +++ fluidsynth-2.4.4+dfsg/debian/changelog 2026-08-30 19:13:05.000000000 +0200 @@ -1,3 +1,10 @@ +fluidsynth (2.4.4+dfsg-1+deb13u3) trixie; urgency=medium + + * CVE-2026-58264 + * CVE-2026-61714 + + -- Moritz Mühlenhoff <[email protected]> Sun, 30 Aug 2026 19:13:05 +0200 + fluidsynth (2.4.4+dfsg-1+deb13u2) trixie; urgency=medium * CVE-2025-56225 diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch --- fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch 1970-01-01 01:00:00.000000000 +0100 +++ fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-58264.patch 2026-08-28 12:11:54.000000000 +0200 @@ -0,0 +1,17 @@ +From 762a3bd39a431cd45abf3bbcce7286c87909d087 Mon Sep 17 00:00:00 2001 +From: derselbst <[email protected]> +Date: Fri, 19 Jun 2026 20:11:54 +0200 +Subject: [PATCH] Fix a heap-based buffer overrun in pitch_bend_range command + +--- fluidsynth-2.4.4+dfsg.orig/src/bindings/fluid_cmd.c ++++ fluidsynth-2.4.4+dfsg/src/bindings/fluid_cmd.c +@@ -795,8 +795,7 @@ fluid_handle_pitch_bend_range(void *data + + channum = atoi(av[0]); + value = atoi(av[1]); +- fluid_channel_set_pitch_wheel_sensitivity(handler->synth->channel[channum], value); +- return FLUID_OK; ++ return fluid_synth_pitch_wheel_sens(handler->synth, channum, value); + } + + int diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch --- fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch 1970-01-01 01:00:00.000000000 +0100 +++ fluidsynth-2.4.4+dfsg/debian/patches/CVE-2026-61714.patch 2026-08-28 12:12:45.000000000 +0200 @@ -0,0 +1,39 @@ +From 772702e00cc6acc7c607efb40283e2269211effc Mon Sep 17 00:00:00 2001 +From: derselbst <[email protected]> +Date: Sat, 27 Jun 2026 08:51:10 +0200 +Subject: [PATCH] Fix heap buffer overflow in MIDI player GHSA-976m-35rw-h3m6 + +--- fluidsynth-2.4.4+dfsg.orig/src/midi/fluid_midi.c ++++ fluidsynth-2.4.4+dfsg/src/midi/fluid_midi.c +@@ -1617,10 +1617,11 @@ fluid_track_send_events(fluid_track_t *t + { + if(player->playback_callback) + { ++ int *chan_is_playing = &player->channel_isplaying[event->channel % MAX_NUMBER_OF_CHANNELS]; + player->playback_callback(player->playback_userdata, event); +- if(event->type == NOTE_ON && event->param2 != 0 && !player->channel_isplaying[event->channel]) ++ if(event->type == NOTE_ON && event->param2 != 0 && !*chan_is_playing) + { +- player->channel_isplaying[event->channel] = TRUE; ++ *chan_is_playing = TRUE; + } + } + } +@@ -2138,7 +2139,7 @@ fluid_player_callback(void *data, unsign + { + if(fluid_atomic_int_get(&player->stopping)) + { +- for(i = 0; i < synth->midi_channels; i++) ++ for(i = 0; i < MAX_NUMBER_OF_CHANNELS; i++) + { + if(player->channel_isplaying[i]) + { +@@ -2186,7 +2187,7 @@ fluid_player_callback(void *data, unsign + seek_ticks = fluid_atomic_int_get(&player->seek_ticks); + if(seek_ticks >= 0) + { +- for(i = 0; i < synth->midi_channels; i++) ++ for(i = 0; i < MAX_NUMBER_OF_CHANNELS; i++) + { + if(player->channel_isplaying[i]) + { diff -Nru fluidsynth-2.4.4+dfsg/debian/patches/series fluidsynth-2.4.4+dfsg/debian/patches/series --- fluidsynth-2.4.4+dfsg/debian/patches/series 2026-03-04 20:50:16.000000000 +0100 +++ fluidsynth-2.4.4+dfsg/debian/patches/series 2026-08-28 12:12:34.000000000 +0200 @@ -1 +1,3 @@ CVE-2025-56225.patch +CVE-2026-58264.patch +CVE-2026-61714.patch