Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19968

Опубликовано: 17 авг. 2026
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.

A flaw was found in Open Asset Import Library Assimp. A remote attacker could exploit a heap-based buffer overflow vulnerability in the ReadFaces_3DGS_MDL7 function of the 3DGS MDL7 Model Parser by providing a specially crafted 3DGS MDL7 model file. This could lead to a denial of service.

Отчет

This Moderate impact flaw in Assimp's 3DGS MDL7 Model Parser could lead to a denial of service. Exploitation requires a user to process a specially crafted 3DGS MDL7 model file, limiting the attack vector to scenarios involving untrusted input.

Меры по смягчению последствий

To reduce the risk of exploitation, avoid processing untrusted 3DGS MDL7 model files with applications that use the Assimp library. Limiting the handling of such files to trusted sources is advised.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10qt6-qtquick3dFix deferred
Red Hat Enterprise Linux 9qt5-qt3dFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2517287assimp: Assimp: Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser

EPSS

Процентиль: 31%
0.00373
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
5 дней назад

A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.

CVSS3: 4.3
nvd
5 дней назад

A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.

CVSS3: 4.3
debian
5 дней назад

A weakness has been identified in Open Asset Import Library Assimp 17c ...

CVSS3: 4.3
github
5 дней назад

A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue.

EPSS

Процентиль: 31%
0.00373
Низкий

4.3 Medium

CVSS3

Уязвимость CVE-2026-19968