<Vulnerability name="CVE-2026-10232">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-06-01T06:30:10</PublicDate>
    <Bugzilla id="2486783" url="https://bugzilla.redhat.com/show_bug.cgi?id=2486783" xml:lang="en:us">
assimp: Assimp: Use-after-free vulnerability allows local impact
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-825</CWE>
    <Details xml:lang="en:us" source="Mitre">
A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Assimp. This vulnerability, a use-after-free, exists in the aiNode::~aiNode function within the ASE File Parser component. A local attacker could exploit this by manipulating specific data, potentially leading to information disclosure, data corruption, or a denial of service (DoS).
    </Details>
    <Statement xml:lang="en:us">
This Moderate impact use-after-free flaw in Assimp's ASE File Parser component allows a local attacker to cause information disclosure, data corruption, or a denial of service. Exploitation requires the attacker to have local access and manipulate specific 3D model data, limiting the attack vector to scenarios where untrusted files are processed.
    </Statement>
    <Mitigation xml:lang="en:us">
To reduce exposure, avoid processing untrusted 3D model files, especially those in the ASE format, with applications that use the Assimp library. If processing untrusted input is unavoidable, consider sandboxing the affected applications to limit potential impact. This operational control may affect functionality if applications depend on processing untrusted ASE files.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>qt6-qtquick3d</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>qt5-qt3d</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-10232
https://nvd.nist.gov/vuln/detail/CVE-2026-10232
https://github.com/assimp/assimp/
https://github.com/assimp/assimp/issues/6617
https://github.com/user-attachments/files/27200601/poc.zip
https://vuldb.com/cve/CVE-2026-10232
https://vuldb.com/submit/821192
https://vuldb.com/vuln/367511
https://vuldb.com/vuln/367511/cti
    </References>
</Vulnerability>