Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://gitlab.kitware.com/vtk/vtk/-/issues/19736 |
|
History
Fri, 31 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-416 | |
| Metrics |
cvssV3_1
|
Fri, 31 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-31T19:07:13.950Z
Reserved: 2025-08-17T00:00:00.000Z
Link: CVE-2025-57108
Updated: 2025-10-31T19:06:23.394Z
Status : Received
Published: 2025-10-31T15:15:42.550
Modified: 2025-10-31T20:15:45.967
Link: CVE-2025-57108
No data.
OpenCVE Enrichment
No data.