Junglewise Threat Intelligence

CVE-2026-41445: KissFFT integer overflow in kiss_fftndr_alloc

CVE-2026-41445 · Severity: high · CVSS 8.8 · Published 2026-04-20

Executive brief

KissFFT is a library used by developers to perform mathematical calculations known as Fast Fourier Transforms. A flaw in how the library calculates memory requirements allows a specially crafted input to cause a memory error. This could lead to a program crash or allow an attacker to execute unauthorized code on the system using the library.

Technical details

An integer overflow vulnerability exists in the `kiss_fftndr_alloc()` function within `kiss_fftndr.c`. The vulnerability occurs during the calculation of the allocation size: `dimOther*(dimReal+2)*sizeof(kiss_fft_scalar)`. This calculation uses signed 32-bit integer arithmetic, which can overflow before being widened to `size_t`. This results in `malloc()` allocating an undersized buffer. When `kiss_fftndr()` subsequently processes data using these dimensions, it performs out-of-bounds writes to the heap. An attacker can exploit this by providing malicious dimensions, potentially leading to arbitrary code execution. The issue is fixed in commit 8a8e66e.

Affected products

  • mborgerding KissFFT before commit 8a8e66e

Timeline

  • 2026-04-20: disclosed
  • 2026-04-20: advisory

References

Related threats