<Vulnerability name="CVE-2026-10198">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-05-31T22:15:12</PublicDate>
    <Bugzilla id="2483754" url="https://bugzilla.redhat.com/show_bug.cgi?id=2483754" xml:lang="en:us">
assimp: Assimp: Denial of Service via null pointer dereference in glTFImporter
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.0</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-476</CWE>
    <Details xml:lang="en:us" source="Mitre">
A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been published and may be used. The project tagged the reported issue as bug.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Assimp, specifically within the glTFImporter component. A local attacker could exploit a null pointer dereference vulnerability in the `Assimp::glTFImporter::ImportMeshes` function. This could lead to a denial of service (DoS) by causing the application to crash.
    </Details>
    <Statement xml:lang="en:us">
A Moderate impact null pointer dereference flaw was found in Assimp's glTFImporter component. This vulnerability allows a local attacker to trigger a denial of service by providing a specially crafted glTF file, causing applications utilizing Assimp to crash. The local nature of the attack limits its overall impact.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>qt6-qtquick3d</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Affected</FixState>
        <PackageName>qt5-qt3d</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-10198
https://nvd.nist.gov/vuln/detail/CVE-2026-10198
https://github.com/assimp/assimp/
https://github.com/assimp/assimp/issues/6609
https://github.com/user-attachments/files/27193865/poc.zip
https://vuldb.com/cve/CVE-2026-10198
https://vuldb.com/submit/821178
https://vuldb.com/vuln/367478
https://vuldb.com/vuln/367478/cti
    </References>
</Vulnerability>