Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10200

Опубликовано: 31 мая 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The project tagged the reported issue as bug.

A flaw was found in Assimp. A local attacker could trigger a heap-based buffer overflow in the glTFCommon::CopyValue function, part of the 4x4 Matrix Parser component. This vulnerability could lead to limited information disclosure, denial of service, or other impacts on system integrity and availability.

Отчет

This Moderate-severity heap-based buffer overflow in Assimp's glTFCommon::CopyValue function allows a local attacker to cause information disclosure, denial of service, or other impacts by manipulating 4x4 matrix parsing. Exploitation requires local access to the system.

Меры по смягчению последствий

To mitigate this issue, users should avoid processing untrusted 3D model files with applications that utilize the Assimp library. Restricting local user access to systems where Assimp is used to process potentially untrusted data can also reduce the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dNot affected
Red Hat Enterprise Linux 9qt5-qt3dFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2483757assimp: Assimp: Heap-based buffer overflow in glTFCommon::CopyValue function

EPSS

Процентиль: 3%
0.00124
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The project tagged the reported issue as bug.

CVSS3: 5.3
nvd
3 месяца назад

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The project tagged the reported issue as bug.

CVSS3: 5.3
debian
3 месяца назад

A vulnerability was found in Assimp up to 6.0.4. This affects the func ...

CVSS3: 5.3
github
3 месяца назад

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The project tagged the reported issue as bug.

suse-cvrf
около 1 месяца назад

Security update for assimp

EPSS

Процентиль: 3%
0.00124
Низкий

5.3 Medium

CVSS3