CVE-2026-41257: Signed Int Overflow Realloc Offset
A signed integer is used to compute memory size via multiplication, passed to an allocation function, and then used to calculate memory offsets. When the multiplication overflows, the signed integer becomes negative. This causes out-of-bounds pointer arithmetic during memory operations, leading to arbitrary memory modification. Use `size_t` for size tracking
greprules fetch cve-2026-41257-signed-int-overflow-realloc-offset --engine opengrepDescription
A signed integer is used to compute memory size via multiplication, passed to an allocation function, and then used to calculate memory offsets. When the multiplication overflows, the signed integer becomes negative. This causes out-of-bounds pointer arithmetic during memory operations, leading to arbitrary memory modification. Use `size_t` for size tracking
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.