Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14610

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.

A flaw was found in Open Asset Import Library Assimp. This vulnerability, a heap-based buffer overflow, allows a local attacker to manipulate input when processing CSM files. Successful exploitation could lead to information disclosure, compromise of data integrity, or a denial of service (DoS).

Отчет

A heap-based buffer overflow in the Open Asset Import Library (Assimp) allows a local attacker to cause information disclosure and a denial of service by processing a specially crafted CSM file. Exploitability is limited by the requirement for local system access.

Меры по смягчению последствий

Do not process Character Studio Motion (.csm) files from untrusted sources. If CSM support is not required, mitigate the flaw by rebuilding Assimp with the ASSIMP_BUILD_NO_CSM_IMPORTER flag enabled, or by configuring Qt 3D and Qt Quick 3D to block .csm asset imports at the application level.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dFix deferred
Red Hat Enterprise Linux 9qt5-qt3dFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=2496974assimp: Open Asset Import Library Assimp: Heap-based buffer overflow allows local information disclosure and denial of service

EPSS

Процентиль: 3%
0.00128
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.

CVSS3: 5.3
nvd
около 2 месяцев назад

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.

CVSS3: 5.3
debian
около 2 месяцев назад

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. ...

CVSS3: 5.3
github
около 2 месяцев назад

A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.

EPSS

Процентиль: 3%
0.00128
Низкий

5.3 Medium

CVSS3