Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10229

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project tagged the reported issue as bug.

A flaw was found in Assimp, a library used for importing and exporting various 3D model formats. This vulnerability, a heap-based buffer overflow, exists within the HL1MDLLoader::read_meshes function of the Half-Life 1 MDL Loader component. A local attacker could exploit this by providing specially crafted input, which may lead to a denial of service, information disclosure, or other impacts on system integrity.

Отчет

This Moderate flaw in Assimp's Half-Life 1 MDL Loader component, specifically within the HL1MDLLoader::read_meshes function, is a heap-based buffer overflow. Exploitation requires a local attacker to provide specially crafted input, which could lead to denial of service or information disclosure. While the exploit is publicly known, the local attack vector limits its immediate impact on typical Red Hat deployments.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dFix deferred
Red Hat Enterprise Linux 9qt5-qt3dFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2486785assimp: Assimp: Heap-based buffer overflow in Half-Life 1 MDL Loader

EPSS

Процентиль: 3%
0.00125
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project tagged the reported issue as bug.

CVSS3: 5.3
nvd
3 месяца назад

A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project tagged the reported issue as bug.

CVSS3: 5.3
debian
3 месяца назад

A vulnerability was determined in Assimp up to 6.0.4. This affects the ...

CVSS3: 5.3
github
3 месяца назад

A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project tagged the reported issue as bug.

EPSS

Процентиль: 3%
0.00125
Низкий

4.8 Medium

CVSS3