CVE-2026-41445 PUBLISHED

KissFFT Integer Overflow Heap Buffer Overflow via kiss_fftndr_alloc()

Assigner: VulnCheck
Reserved: 20.04.2026 Published: 20.04.2026 Updated: 20.04.2026

KissFFT before commit 8a8e66e contains an integer overflow vulnerability in the kiss_fftndr_alloc() function in kiss_fftndr.c where the allocation size calculation dimOther(dimReal+2)sizeof(kiss_fft_scalar) overflows signed 32-bit integer arithmetic before being widened to size_t, causing malloc() to allocate an undersized buffer. Attackers can trigger heap buffer overflow by providing crafted dimensions that cause the multiplication to exceed INT_MAX, allowing writes beyond the allocated buffer region when kiss_fftndr() processes the data.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor mborgerding
Product kissfft
Versions Default: unaffected
  • affected from 0 to 8a8e66e33d692bad1376fe7904d87d767730537f (excl.)

Credits

  • Sajeeb Lohani finder
  • VulnCheck coordinator

References

Problem Types

  • CWE-190 Integer Overflow or Wraparound CWE
  • CWE-122 Heap-based Buffer Overflow CWE