CVE-2025-15647 PUBLISHED

CDT before 1.4.5 Out-of-Bounds Read via opposedVertexInd

Assigner: VulnCheck
Reserved: 22.05.2026 Published: 05.09.2026 Updated: 05.09.2026

CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round outside adjacent triangles. Attackers can supply nearly-degenerate constraint edges through geometry data to trigger an out-of-bounds array access that crashes the calling process.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor artem-ogre
Product CDT
Versions Default: unaffected
  • affected from 0 to 1.4.5 (excl.)

Credits

  • Vlatko Kosturjak reporter

References

Problem Types

  • Out-of-bounds Read CWE