Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-48977— OpenSlide: Arbitrary memory write with crafted Ventana BIF file

Quick assessment

Affected
openslide openslide
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OpenSlide 是一个用于读取全切片图像文件的 C 语言库。从版本 3.4.1 到 4.0.1,OpenSlide 在 中的 函数在处理经过精心构造的 Ventana BIF 文件时,会接受非正数(零或负数)的行或列瓦片数量。这些无效的数量会导致由攻击者控制的相对内存偏移,并允许在这些偏移处写入任意值,影响所有受支持的平台和配置,最终可能导致程序崩溃或潜在的任意代码执行。该问题已在版本 4.0.1 中修复。

CVSS 7.7 · High EPSS 0.30% · P22

Affected Version Matrix 1

VendorProduct Version RangeStatus
openslide openslide >= 3.4.1, < 4.0.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-48977

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OpenSlide: Arbitrary memory write with crafted Ventana BIF file
Source: CVE Program / CVE List V5
Vulnerability Description
OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF file. The invalid counts produce attacker-controlled relative memory offsets and allow arbitrary values to be written at those offsets, affecting all supported platforms and configurations and resulting in a crash or potential arbitrary code execution. This issue is fixed in version 4.0.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
任意地址可写任意内容条件
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
openslide openslide >= 3.4.1, < 4.0.1 -

II. Public POCs for CVE-2026-48977

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-48977

登录查看更多情报信息。

Patches & Fixes for CVE-2026-48977 (2)

Vendor Advisories for CVE-2026-48977 (1)

Vendor Pages for CVE-2026-48977 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-48977

No comments yet


Leave a comment