Bug 2408881 (CVE-2025-57108) - CVE-2025-57108 Kitware VTK: vtk: From CVEorg collector
Summary: CVE-2025-57108 Kitware VTK: vtk: From CVEorg collector
Keywords:
Status: NEW
Alias: CVE-2025-57108
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
unspecified
unspecified
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2411755 2411759 2411763 2411766 2411768 2411769
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-31 16:01 UTC by OSIDB Bzimport
Modified: 2025-11-01 17:56 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-10-31 16:01:58 UTC
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector members are accessed after the underlying memory has been freed, specifically when handling GLTF files with corrupted or invalid mesh reference structures.


Note You need to log in before you can comment on or make changes to this bug.