Executive brief
KissFFT is a popular library used for performing Fast Fourier Transforms in various software applications. A flaw in how the library handles memory allocation on 32-bit systems could allow an attacker to cause a system crash or potentially execute unauthorized code. This occurs when the library is asked to process extremely large datasets, leading to a memory corruption event.
Technical details
An integer overflow exists in the kiss_fft_alloc() function within kiss_fft.c. The 'nfft' parameter is used in a size calculation (sizeof(kiss_fft_cpx) * (nfft - 1)) without prior validation. On 32-bit architectures where size_t is 32 bits, a sufficiently large 'nfft' value causes the calculation to wrap around, resulting in a small value being passed to malloc(). Subsequent initialization loops then write data based on the original large 'nfft' value, leading to a heap buffer overflow. This vulnerability is specific to 32-bit systems and was addressed in commit 1b083165 by adding bounds checking for the 'nfft' parameter.
Affected products
- mborgerding KissFFT versions prior to commit 1b083165
Timeline
- 2025-10-27: disclosed: Issue reported to vendor via VulnCheck
- 2025-12-01: advisory: NVD and VulnCheck published advisory
- 2025-12-01: patched: Fix committed to main branch