Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10197

Опубликовано: 31 мая 2026
Источник: redhat
CVSS3: 5.5

Описание

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue. The pull request to fix this issue awaits acceptance.

A flaw was found in Assimp. A local user with access to the system could exploit a null pointer dereference vulnerability in the glTF2Importer::ImportEmbeddedTextures function. This flaw could lead to a Denial of Service (DoS), making the application unavailable.

Отчет

This Moderate impact null pointer dereference vulnerability in Assimp's glTF2Importer requires local system access to trigger a Denial of Service. While the flaw can make an application unavailable, its local nature limits the overall risk to Red Hat products.

Меры по смягчению последствий

Users should avoid processing untrusted glTF2 files with applications that rely on the Assimp library. This vulnerability requires local access and the processing of a specially crafted file to trigger the null pointer dereference, leading to a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dNot affected
Red Hat Enterprise Linux 9qt5-qt3dFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2483755assimp: Assimp: Denial of Service via null pointer dereference in glTF2Importer

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
3 месяца назад

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue. The pull request to fix this issue awaits acceptance.

CVSS3: 3.3
nvd
3 месяца назад

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue. The pull request to fix this issue awaits acceptance.

CVSS3: 3.3
debian
3 месяца назад

A vulnerability was detected in Assimp up to 6.0.4. Affected is the fu ...

CVSS3: 3.3
github
3 месяца назад

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue. The pull request to fix this issue awaits acceptance.

suse-cvrf
около 1 месяца назад

Security update for assimp

5.5 Medium

CVSS3