Описание
Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string members of mesh objects that have been previously freed during actor import operations.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | deferred | 2026-04-13 |
| esm-apps/jammy | deferred | 2026-04-13 |
| esm-apps/noble | deferred | 2026-04-13 |
| esm-apps/resolute | deferred | 2026-04-13 |
| jammy | deferred | 2026-04-13 |
| noble | deferred | 2026-04-13 |
| plucky | ignored | end of life, was needs-triage |
| questing | ignored | end of life, was deferred [2026-04-13] |
| resolute | deferred | 2026-04-13 |
| upstream | deferred | 2026-04-13 |
Показывать по
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string members of mesh objects that have been previously freed during actor import operations.
Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-Af ...
Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When processing GLTF files with invalid scene node references, the application accesses string members of mesh objects that have been previously freed during actor import operations.
EPSS
6.5 Medium
CVSS3