Bug 2407262 (CVE-2025-14439, GHSA-grjp-54v3-c442)

Summary: CVE-2025-14439 usd: OpenUSD: Remote Code Execution via a specially crafted file
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A use-after-free vulnerability has been identified in the USD (Universal Scene Description) framework when processing specially crafted crate files containing invalid primChildren entries. Improper validation of malformed or duplicate entries may lead to memory access after free conditions during child traversal. An attacker could exploit this issue by supplying a malicious USD crate file that triggers memory corruption during import or parsing, potentially resulting in application crashes or execution of arbitrary code.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2422275, 2422276    
Bug Blocks:    

Description OSIDB Bzimport 2025-10-29 23:06:00 UTC
# Patch
This is fixed with [commit b953092](https://github.com/PixarAnimationStudios/OpenUSD/commit/b9530922b6a8ea72cd43661226b693fff8abbe4c), with the fix available in OpenUSD 25.11 and onwards.

# Summary
We have been advised by Zero Day Initiative that our usage of the USD framework may constitute a Use-After-Free Remote Code Execution Vulnerability. They have sent us the attached file illustrating the issue. Indeed, we see a use after free exception when running the file through our importer with an address sanitizer.

[zdi-23709-poc0.zip](https://github.com/user-attachments/files/17474297/zdi-23709-poc0.zip)

Thanks in advance.