Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10198

Опубликовано: 31 мая 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been published and may be used. The project tagged the reported issue as bug.

A flaw was found in Assimp, specifically within the glTFImporter component. A local attacker could exploit a null pointer dereference vulnerability in the Assimp::glTFImporter::ImportMeshes function. This could lead to a denial of service (DoS) by causing the application to crash.

Отчет

A Moderate impact null pointer dereference flaw was found in Assimp's glTFImporter component. This vulnerability allows a local attacker to trigger a denial of service by providing a specially crafted glTF file, causing applications utilizing Assimp to crash. The local nature of the attack limits its overall impact.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dNot affected
Red Hat Enterprise Linux 9qt5-qt3dAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2483754assimp: Assimp: Denial of Service via null pointer dereference in glTFImporter

EPSS

Процентиль: 2%
0.00113
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
3 месяца назад

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been published and may be used. The project tagged the reported issue as bug.

CVSS3: 3.3
nvd
3 месяца назад

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been published and may be used. The project tagged the reported issue as bug.

CVSS3: 3.3
debian
3 месяца назад

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerab ...

CVSS3: 3.3
github
3 месяца назад

A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been published and may be used. The project tagged the reported issue as bug.

EPSS

Процентиль: 2%
0.00113
Низкий

5 Medium

CVSS3