CVE-2021-28421: Use After Free
(updated )
FluidSynth contains a use after free vulnerability in sfloader/fluid_sffile.c
that can result in arbitrary code execution or a denial of service (DoS) if a malicious soundfont2 file is loaded into a fluidsynth library.
References
Detect and mitigate CVE-2021-28421 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →