Executive brief
OpenSlide is a C library used to read medical whole slide images from digital pathology scanners. A crafted Ventana BIF image file can cause the library to write arbitrary values to attacker-controlled memory locations, leading to application crashes or potentially allowing code execution on systems that process untrusted slide images.
Technical details
OpenSlide's parse_level0_xml() function in src/openslide-vendor-ventana.c fails to validate tile row and column counts from Ventana BIF files. An attacker can supply nonpositive (zero or negative) tile counts in a malicious BIF file, which are then used to compute relative memory offsets without bounds checking. This allows writing arbitrary values at attacker-controlled memory locations. The vulnerability affects all OpenSlide versions from 3.4.1 through 4.0.0 and is fixed in version 4.0.1. No authentication or user interaction is required beyond opening a malicious image file.
Affected products
- OpenSlide OpenSlide 3.4.1 through 4.0.0
Timeline
- 2026-09-17: disclosed
- 2026-06-06: patched: Fixed in version 4.0.1