<Vulnerability name="CVE-2026-10201">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-05-31T23:00:12</PublicDate>
    <Bugzilla id="2483758" url="https://bugzilla.redhat.com/show_bug.cgi?id=2483758" xml:lang="en:us">
assimp: Assimp: Denial of Service via divide-by-zero in FBXExporter
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-369</CWE>
    <Details xml:lang="en:us" source="Mitre">
A vulnerability was determined in Assimp up to 6.0.4. This vulnerability affects the function FBXExporter::WriteObjects of the file FBXExporter.cpp of the component UV Channel Handler. Executing a manipulation can lead to divide by zero. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Applying a patch is advised to resolve this issue. The project tagged the reported issue as bug.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Assimp. A local user can perform a manipulation within the FBXExporter::WriteObjects function, leading to a divide-by-zero error. This vulnerability can cause a Denial of Service (DoS), making the application unavailable.
    </Details>
    <Statement xml:lang="en:us">
Moderate: A local denial of service flaw was found in Assimp's FBX exporter. This issue allows a local attacker to trigger a divide-by-zero error by manipulating the FBX export process, leading to application unavailability. Exploitation requires an application to utilize the vulnerable FBX export functionality.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>qt6-qtquick3d</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>qt5-qt3d</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-10201
https://nvd.nist.gov/vuln/detail/CVE-2026-10201
https://github.com/assimp/assimp/
https://github.com/assimp/assimp/issues/6613
https://github.com/user-attachments/files/27153727/poc.zip
https://vuldb.com/cve/CVE-2026-10201
https://vuldb.com/submit/821182
https://vuldb.com/vuln/367481
https://vuldb.com/vuln/367481/cti
    </References>
</Vulnerability>