PT-2025-44636 · Kitware+1 · Vtk+1

Published

2025-10-31

·

Updated

2025-10-31

·

CVE-2025-57107

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Kitware VTK (Visualization Toolkit) versions through 9.5.0
Description The software contains a heap buffer overflow issue within the vtkGLTFDocumentLoader. This occurs when processing specifically designed GLTF files, where the copy constructor of Accessor objects does not correctly validate buffer boundaries before reading from memory. The issue is triggered by memory read operations.
Recommendations Update to a version later than 9.5.0.

Exploit

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-57107
PYSEC-2025-225

Affected Products

Debian
Vtk