CVE-2025-34297Patch

LOWCVSS 8.6 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

KissFFT versions prior to the fix commit 1b083165 contain an integer overflow in kiss_fft_alloc() in kiss_fft.c on platforms where size_t is 32-bit. The nfft parameter is not validated before being used in a size calculation (sizeof(kiss_fft_cpx) * (nfft - 1)), which can wrap to a small value when nfft is large. As a result, malloc() allocates an undersized buffer and the subsequent twiddle-factor initialization loop writes nfft elements, causing a heap buffer overflow. This vulnerability only affects 32-bit architectures.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-19: 4Patch / Workaround · 2026-03-19: 4Technical Details · 2026-03-19: 403-19
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical patch for kiss-fft on #Fedora 42/43 is out. Version 131.2.0 fixes CVE-2025-34297 (integer overflow -> heap buffer overflow). Read more: 👉 https://tinyurl.com/5n7n8p4b #Security https://t.co/FocmGWRuGU

    Post summary

    A critical patch (version 131.2.0) for kiss-fft on Fedora 42/43 has been released to fix CVE‑2025‑34297, an integer overflow that could result in a heap buffer overflow.

    00010118
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical patch for kiss-fft on #Fedora 42/43 is out. Version 131.2.0 fixes CVE-2025-34297 (integer overflow -> heap buffer overflow). If you're doing any FFT work, patch now. Read more: 👉 https://tinyurl.com/mthfkwba #Security https://t.co/X3yV9xNmig

    Post summary

    CVE‑2025‑34297 in kiss‑fft causes an integer‑overflow‑to‑heap‑buffer‑overflow vulnerability; a critical patch (v131.2.0) is available for Fedora 42/43, and users working with FFTs are urged to upgrade immediately.

    00000115
    1.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #Fedora 43: Critical #KISSFFT update (131.2.0) fixes CVE-2025-34297. This integer overflow leads to a heap buffer overflow in kiss_fft_alloc(), risking RCE. Read more: 👉 https://tinyurl.com/y9wm42jp #Security https://t.co/SASLcqCBFK

    Post summary

    Fedora 43 update 131.2.0 patches CVE‑2025‑34297, an integer‑overflow RCE risk; no PoC or active exploitation details are provided.

    00000113
    1.5K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    CVE-2025-34297: Critical buffer overflow in KISS FFT used by Fedora 42 and 43, exploitable via kiss_fft_alloc; patched in v131.2.0, users should update with dnf. #Vulnerability https://threatcluster.io/cluster/critical-buffer-overflow-vulnerability-in-kiss-fft-affects-f-a379a6a8

    Post summary

    The tweet announces a critical buffer overflow in KISS FFT (CVE‑2025‑34297) affecting Fedora 42/43, highlights the vulnerable function kiss_fft_alloc, and advises users to update via dnf, without providing a PoC or evidence of active exploitation.

    0000062
    106 followersView on X

Explore more