PT-2025-44445 · Kitware+1 · Vtk+1

Published

2025-10-30

·

Updated

2025-10-30

·

CVE-2025-57109

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions Kitware VTK (Visualization Toolkit) version 9.5.0
Description The software contains a flaw related to Heap Use-After-Free within the vtkGLTFImporter::ImportActors function. This occurs when processing GLTF files containing invalid scene node references, leading to access of string members in mesh objects that have already been freed during actor import.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2025-57109

Affected Products

Debian
Vtk