CVE-2025-57106

Name
CVE-2025-57106
Description
Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing GLTF accessor data.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://gitlab.kitware.com/vtk/vtk/-/issues/19733
cve@mitre.org https://gitlab.kitware.com/vtk/vtk/-/issues/19734

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:vtk:vtk:*:*:*:*:*:*:*:* vtk >= None <= 9.5.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vtk edge-community 9.3.1-r3 None possibly vulnerable
vtk edge-community 9.3.1-r2 None possibly vulnerable
vtk edge-community 9.3.1-r1 None possibly vulnerable
vtk edge-community 9.3.1-r0 None possibly vulnerable
vtk 3.22-community 9.3.1-r1 None possibly vulnerable
vtk 3.22-community 9.3.1-r0 None possibly vulnerable