PT-2025-44637 · Kitware+1 · Vtk+1

Published

2025-10-31

·

Updated

2025-10-31

·

CVE-2025-57108

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kitware VTK (Visualization Toolkit) versions through 9.5.0
Description The software contains a heap use-after-free issue in vtkGLTFDocumentLoader. This occurs during mesh object copy operations, where vector members are accessed after the memory has been freed. The issue is triggered when processing GLTF files containing corrupted or invalid mesh reference structures.
Recommendations Versions prior to 9.5.0 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2025-57108
PYSEC-2025-226

Affected Products

Debian
Vtk