Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-10232

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.

A flaw was found in Assimp. This vulnerability, a use-after-free, exists in the aiNode::~aiNode function within the ASE File Parser component. A local attacker could exploit this by manipulating specific data, potentially leading to information disclosure, data corruption, or a denial of service (DoS).

Отчет

This Moderate impact use-after-free flaw in Assimp's ASE File Parser component allows a local attacker to cause information disclosure, data corruption, or a denial of service. Exploitation requires the attacker to have local access and manipulate specific 3D model data, limiting the attack vector to scenarios where untrusted files are processed.

Меры по смягчению последствий

To reduce exposure, avoid processing untrusted 3D model files, especially those in the ASE format, with applications that use the Assimp library. If processing untrusted input is unavoidable, consider sandboxing the affected applications to limit potential impact. This operational control may affect functionality if applications depend on processing untrusted ASE files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dFix deferred
Red Hat Enterprise Linux 9qt5-qt3dFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2486783assimp: Assimp: Use-after-free vulnerability allows local impact

EPSS

Процентиль: 2%
0.00115
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.

CVSS3: 5.3
nvd
3 месяца назад

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.

CVSS3: 5.3
debian
3 месяца назад

A weakness has been identified in Assimp up to 6.0.4. Affected by this ...

CVSS3: 5.3
github
3 месяца назад

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.

suse-cvrf
около 1 месяца назад

Security update for assimp

EPSS

Процентиль: 2%
0.00115
Низкий

5.3 Medium

CVSS3