CVE-2025-57107

Name
CVE-2025-57107
Description
Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accessor objects fails to properly validate buffer boundaries before performing memory read operations.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://gitlab.kitware.com/vtk/vtk/-/issues/19732

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:vtk:vtk:*:*:*:*:*:*:*:* vtk >= None <= 9.5.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
vtk edge-community 9.3.1-r3 None possibly vulnerable
vtk edge-community 9.3.1-r2 None possibly vulnerable
vtk edge-community 9.3.1-r1 None possibly vulnerable
vtk edge-community 9.3.1-r0 None possibly vulnerable
vtk 3.22-community 9.3.1-r1 None possibly vulnerable
vtk 3.22-community 9.3.1-r0 None possibly vulnerable