An update that solves one vulnerability and has one bug fix can now be installed.. openSUSE security update: security update for fluidsynth ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:20291-1 Rating: important References: * bsc#1256435 Cross-References: * CVE-2025-56225 CVSS scores: * CVE-2025-56225 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-56225 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability and has one bug fix can now be installed. Description: This update for fluidsynth fixes the following issues: - CVE-2025-56225: NULL pointer deference when loading and invalid MIDI file (bsc#1256435). Patch instructions: To install this openSUSE security update use the suse recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-329=1 Package List: - openSUSE Leap 16.0: fluidsynth-2.3.5-160000.3.1 fluidsynth-devel-2.3.5-160000.3.1 libfluidsynth3-2.3.5-160000.3.1 References: * https://www.suse.com/security/cve/CVE-2025-56225.html . An important security update for openSUSE fluidsynth fixes a NULL pointer dereference vulnerability. Patch now.. openSUSE, fluidsynth, security patch, IMPORTANT update, software vulnerabilities. . Severity: Important. LinuxSecurity.com Team
An update that fixes one vulnerability is now available.. openSUSE Security Update: Security update for fluidsynth ______________________________________________________________________________ Announcement ID: openSUSE-SU-2026:0014-1 Rating: moderate References: #1256435 Cross-References: CVE-2025-56225 CVSS scores: CVE-2025-56225 (SUSE): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: openSUSE Backports SLE-15-SP7 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for fluidsynth fixes the following issues: - CVE-2025-56225: Fixed NULL pointer deference when loading and invalid MIDI file (boo#1256435). Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP7: zypper in -t patch openSUSE-2026-14=1 Package List: - openSUSE Backports SLE-15-SP7 (aarch64 i586 ppc64le s390x x86_64): fluidsynth-2.3.4-bp157.2.3.1 fluidsynth-devel-2.3.4-bp157.2.3.1 libfluidsynth3-2.3.4-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (aarch64_ilp32): libfluidsynth3-64bit-2.3.4-bp157.2.3.1 - openSUSE Backports SLE-15-SP7 (x86_64): libfluidsynth3-32bit-2.3.4-bp157.2.3.1 References: https://www.suse.com/security/cve/CVE-2025-56225.html https://bugzilla.suse.com/1256435 . An update for fluidsynth is now available addressing a moderate security issue that leads to a NULL pointer deference.. openSUSE fluidsynth update security moderate. . LinuxSecurity.com Team
An update that solves one vulnerability can now be installed.. # fluidsynth-2.5.2-2.1 on GA media Announcement ID: openSUSE-SU-2026:10038-1 Rating: moderate Cross-References: * CVE-2025-56225 CVSS scores: * CVE-2025-56225 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-56225 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the fluidsynth-2.5.2-2.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * fluidsynth 2.5.2-2.1 * fluidsynth-devel 2.5.2-2.1 * libfluidsynth3 2.5.2-2.1 * libfluidsynth3-32bit 2.5.2-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-56225.html . A moderate security advisory for openSUSE regarding fluidsynth package, addressing a critical buffer overflow vulnerability.. openSUSE fluidsynth security update CVE-2025-56225 moderate severity. . LinuxSecurity.com Team
This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-afe4be8cb3 2026-01-12 00:55:40.170795+00:00 -------------------------------------------------------------------------------- Name : musescore Product : Fedora 43 Version : 4.6.5 Release : 32.fc43 URL : https://musescore.org/ Summary : Music Composition & Notation Software Description : MuseScore is a free cross platform WYSIWYG music notation program. Some highlights: * WYSIWYG, notes are entered on a "virtual note sheet" * Unlimited number of staves * Up to four voices per staff * Easy and fast note entry with mouse, keyboard or MIDI * Integrated sequencer and FluidSynth software synthesizer * Import and export of MusicXML and Standard MIDI Files (SMF) * Translated in 26 languages -------------------------------------------------------------------------------- Update Information: This update adds a patch to fix CVE-2025-56225, a flaw in the bundled version of fluidsynth. -------------------------------------------------------------------------------- ChangeLog: * Fri Jan 9 2026 Jerry James - 4.6.5-32 - Patch for CVE-2025-56225 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2428300 - CVE-2025-56225 musescore: FluidSynth: Denial of Service via invalid MIDI file processing [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2428300 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-afe4be8cb3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with theFedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
An update that solves one vulnerability can now be installed.. # fluidsynth-2.5.2-1.1 on GA media Announcement ID: openSUSE-SU-2026:10004-1 Rating: moderate Cross-References: * CVE-2025-68617 Affected Products: * openSUSE Tumbleweed An update that solves one vulnerability can now be installed. ## Description: These are all security issues fixed in the fluidsynth-2.5.2-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * fluidsynth 2.5.2-1.1 * fluidsynth-devel 2.5.2-1.1 * libfluidsynth3 2.5.2-1.1 * libfluidsynth3-32bit 2.5.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68617.html . An important moderate security update for fluidsynth addressed critical issues in openSUSE Tumbleweed.. fluidsynth, openSUSE Tumbleweed, security update. . LinuxSecurity.com Team
Update to 2.5.2 Fix for CVE-2025-68617. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-202d079b40 2025-12-29 17:23:59.716712+00:00 -------------------------------------------------------------------------------- Name : fluidsynth Product : Fedora 42 Version : 2.5.2 Release : 1.fc42 URL : http://www.fluidsynth.org/ Summary : Real-time software synthesizer Description : FluidSynth is a real-time software synthesizer based on the SoundFont 2 specifications. It is a "software synthesizer". FluidSynth can read MIDI events from the MIDI input device and render them to the audio device. It features real-time effect modulation using SoundFont 2.01 modulators, and a built-in command line shell. It can also play MIDI files (note: FluidSynth was previously called IIWU Synth). -------------------------------------------------------------------------------- Update Information: Update to 2.5.2 Fix for CVE-2025-68617 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 24 2025 Christoph Karl - 2.5.2-1 - Update to 2.5.2 - Fix for CVE-2025-68617 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2424828 - CVE-2025-68617 fluidsynth: FluidSynth: Race Condition in DLS Unloading Allows Code Execution and Privilege Escalation [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2424828 [ 2 ] Bug #2424831 - CVE-2025-68617 fluidsynth: FluidSynth: Race Condition in DLS Unloading Allows Code Execution and Privilege Escalation [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424831 [ 3 ] Bug #2424833 - CVE-2025-68617 fluidsynth: FluidSynth: Race Condition in DLS Unloading Allows Code Execution and Privilege Escalation [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424833 [ 4 ] Bug #2424835 - CVE-2025-68617 fluidsynth: FluidSynth: RaceCondition in DLS Unloading Allows Code Execution and Privilege Escalation [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2424835 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-202d079b40' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Update to 2.5.2 Fix for CVE-2025-68617. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-16548b7718 2025-12-28 01:06:50.261964+00:00 -------------------------------------------------------------------------------- Name : fluidsynth Product : Fedora 43 Version : 2.5.2 Release : 1.fc43 URL : http://www.fluidsynth.org/ Summary : Real-time software synthesizer Description : FluidSynth is a real-time software synthesizer based on the SoundFont 2 specifications. It is a "software synthesizer". FluidSynth can read MIDI events from the MIDI input device and render them to the audio device. It features real-time effect modulation using SoundFont 2.01 modulators, and a built-in command line shell. It can also play MIDI files (note: FluidSynth was previously called IIWU Synth). -------------------------------------------------------------------------------- Update Information: Update to 2.5.2 Fix for CVE-2025-68617 -------------------------------------------------------------------------------- ChangeLog: * Wed Dec 24 2025 Christoph Karl - 2.5.2-1 - Update to 2.5.2 - Fix for CVE-2025-68617 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2424828 - CVE-2025-68617 fluidsynth: FluidSynth: Race Condition in DLS Unloading Allows Code Execution and Privilege Escalation [epel-10] https://bugzilla.redhat.com/show_bug.cgi?id=2424828 [ 2 ] Bug #2424831 - CVE-2025-68617 fluidsynth: FluidSynth: Race Condition in DLS Unloading Allows Code Execution and Privilege Escalation [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2424831 [ 3 ] Bug #2424833 - CVE-2025-68617 fluidsynth: FluidSynth: Race Condition in DLS Unloading Allows Code Execution and Privilege Escalation [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2424833 [ 4 ] Bug #2424835 - CVE-2025-68617 fluidsynth: FluidSynth: RaceCondition in DLS Unloading Allows Code Execution and Privilege Escalation [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2424835 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-16548b7718' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Fix world writeable /run/lock/fluidsynth Update to 2.4.8. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1131df0f70 2025-10-30 04:33:58.492895+00:00 -------------------------------------------------------------------------------- Name : fluidsynth Product : Fedora 42 Version : 2.4.8 Release : 2.fc42 URL : http://www.fluidsynth.org/ Summary : Real-time software synthesizer Description : FluidSynth is a real-time software synthesizer based on the SoundFont 2 specifications. It is a "software synthesizer". FluidSynth can read MIDI events from the MIDI input device and render them to the audio device. It features real-time effect modulation using SoundFont 2.01 modulators, and a built-in command line shell. It can also play MIDI files (note: FluidSynth was previously called IIWU Synth). -------------------------------------------------------------------------------- Update Information: Fix world writeable /run/lock/fluidsynth Update to 2.4.8 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 20 2025 Christoph Karl - 2.4.8-2 - Fix world writeable /run/lock/fluidsynth * Thu Oct 16 2025 Christoph Karl - 2.4.8-1 - Update to 2.4.8 - Fix world writeable /run/lock/fluidsynth -------------------------------------------------------------------------------- References: [ 1 ] Bug #2404360 - /run/lock/fluidsynth is world-writable https://bugzilla.redhat.com/show_bug.cgi?id=2404360 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1131df0f70' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details onthe GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.