<Vulnerability name="CVE-2026-10231">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-01T06:15:09</PublicDate>
    <Bugzilla id="2486304" url="https://bugzilla.redhat.com/show_bug.cgi?id=2486304" xml:lang="en:us">
assimp: Assimp: Local heap-based buffer overflow allows denial of service or arbitrary code execution
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-131</CWE>
    <Details xml:lang="en:us" source="Mitre">
A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract_anim_value of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Performing a manipulation of the argument num.total results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project tagged the reported issue as bug.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Assimp, a library for importing various 3D model formats. A local attacker could exploit a heap-based buffer overflow vulnerability in the Half-Life 1 MDL Loader component. By manipulating a specific argument, an attacker could cause the application to crash, leading to a denial of service, or potentially execute unauthorized code. This could result in a loss of system availability or compromise of data.
    </Details>
    <Statement xml:lang="en:us">
This Moderate impact flaw in Assimp's Half-Life 1 MDL Loader component, present in Red Hat Enterprise Linux 9 via qt5-qt3d, requires local access to exploit. An attacker could trigger a heap-based buffer overflow by manipulating a specific argument, potentially leading to a denial of service or arbitrary code execution. The local attack vector and the need for specific input limit the overall risk.
    </Statement>
    <Mitigation xml:lang="en:us">
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>qt6-qtquick3d</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>qt5-qt3d</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-10231
https://nvd.nist.gov/vuln/detail/CVE-2026-10231
https://github.com/assimp/assimp/
https://github.com/assimp/assimp/issues/6616
https://github.com/user-attachments/files/27195744/poc.zip
https://vuldb.com/cve/CVE-2026-10231
https://vuldb.com/submit/821191
https://vuldb.com/vuln/367510
https://vuldb.com/vuln/367510/cti
    </References>
</Vulnerability>