<Vulnerability name="CVE-2026-19969">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-17T01:00:15</PublicDate>
    <Bugzilla id="2517289" url="https://bugzilla.redhat.com/show_bug.cgi?id=2517289" xml:lang="en:us">
assimp: Assimp: Buffer overflow in 3DGS MDL7 model processing
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>5.4</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-120</CWE>
    <Details xml:lang="en:us" source="Mitre">
A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted element is the function Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Model Output Mesh Generator. The manipulation leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through an issue report but has not responded yet.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Open Asset Import Library Assimp. A buffer overflow vulnerability exists in the `GenerateOutputMeshes_3DGS_MDL7` function when processing 3DGS MDL7 models. A remote attacker could exploit this to cause a denial of service or potentially disclose sensitive information.
    </Details>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>qt6-qtquick3d</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>qt5-qt3d</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-19969
https://nvd.nist.gov/vuln/detail/CVE-2026-19969
https://github.com/assimp/assimp/issues/6631
https://github.com/user-attachments/files/27425495/poc.zip
https://vuldb.com/cve/CVE-2026-19969
https://vuldb.com/submit/873130
https://vuldb.com/vuln/391146
https://vuldb.com/vuln/391146/cti
    </References>
</Vulnerability>