OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() processing in src/openslide-vendor-ventana.c accepts nonpositive row or column tile counts from a crafted Ventana BIF file. The invalid counts produce attacker-controlled relative memory offsets and allow arbitrary values to be written at those offsets, affecting all supported platforms and configurations and resulting in a crash or potential arbitrary code execution. This issue is fixed in version 4.0.1.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-123",
"CWE-1284",
"CWE-823"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48977.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48977.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"37663368902248290890830212999759190478",
"222598150985970413257920523793620553364",
"110187170279966970021237591102720013962",
"18557327014411702082152728286544279105"
],
"threshold": 0.9
},
"id": "CVE-2026-48977-1a9553c4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openslide/openslide/commit/2be88bd782d9fff46de8e56a99baca523e7917b3",
"target": {
"file": "src/openslide-vendor-ventana.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "224579525781094751088489470525506148291",
"length": 4959
},
"id": "CVE-2026-48977-9f2e09a0",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/openslide/openslide/commit/2be88bd782d9fff46de8e56a99baca523e7917b3",
"target": {
"file": "src/openslide-vendor-ventana.c",
"function": "parse_level0_xml"
}
}
]
"2026-09-25T08:21:37Z"