Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
UBUNTU SECURITY NOTICECANONICALVERIFIED

PUBLISHER UPDATE · USN-8885-1

USN-8885-1 release notes and known issues

USN-8885-1: FluidSynth vulnerabilities

Scope: Ubuntu. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

It was discovered that FluidSynth did not properly validate the channel argument of the pitch_bend_range command. A remote attacker could possibly use this issue to cause FluidSynth to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-58264) It was discovered that FluidSynth incorrectly handled configurations with more than 16 MIDI channels in its MIDI player, leading to a heap buffer overflow. An attacker could possibly use this issue to cause FluidSynth to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61714)

Improvements and security content

  • It was discovered that FluidSynth did not properly validate the channel argument of the pitch_bend_range command. A remote attacker could possibly use this issue to cause FluidSynth to crash, resulting in a denial of service, or execute arbitrary code. (CVE-2026-58264) It was discovered that FluidSynth incorrectly handled configurations with more than 16 MIDI channels in its MIDI player, leading to a heap buffer overflow. An attacker could possibly use this issue to cause FluidSynth to crash, resulting in a denial of service, or execute arbitrary code. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-61714)

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Ubuntu

Affected versions

  • 22.04
  • 24.04
  • 26.04

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

Related vulnerabilities

BlackTree CVE Intelligence

These links connect the publisher update to related Lifecycle records without treating the update publication date as an end-of-support date.

Official publisher evidence

CANONICALVERIFIED

USN-8885-1: FluidSynth vulnerabilities

Checked 7 Oct 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source