Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://gitlab.kitware.com/vtk/vtk/-/issues/19736 |
|
History
Mon, 03 Nov 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vtk
Vtk vtk |
|
| Vendors & Products |
Vtk
Vtk vtk |
Fri, 31 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-416 | |
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-10-31T00:00:00.000Z
Updated: 2025-10-31T19:07:13.950Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57108
Updated: 2025-10-31T19:06:23.394Z
Status : Awaiting Analysis
Published: 2025-10-31T15:15:42.550
Modified: 2025-11-04T15:41:31.450
Link: CVE-2025-57108
No data.
ReportizFlow