OpenSlide C Library Vulnerability in Ventana BIF File Parsing
CVE-2026-48977
7.7HIGH
What is CVE-2026-48977?
The OpenSlide C library, utilized for reading whole slide images, contains a vulnerability in its parse_level0_xml() function. This issue arises due to the handling of nonpositive row or column tile counts from a specially crafted Ventana BIF file. The presence of invalid counts allows attackers to control relative memory offsets, which can lead to the execution of arbitrary code and crashes across all supported platforms and configurations. The vulnerability is addressed in version 4.0.1, highlighting the importance of updating to this release.
Affected Version(s)
openslide >= 3.4.1, < 4.0.1
