Bug 2496580 - CVE-2025-15666 assimp: Assimp: Heap-based buffer overflow via crafted model file [fedora-all]
Summary: CVE-2025-15666 assimp: Assimp: Heap-based buffer overflow via crafted model f...
Keywords:
Status: ON_QA
Alias: None
Product: Fedora
Classification: Fedora
Component: assimp
Version: 45
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Sandro Mani
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["f81d0625-d3dd-422d-853a-a...
Depends On:
Blocks: CVE-2025-15666
TreeView+ depends on / blocked
 
Reported: 2026-07-02 15:27 UTC by Ganesh
Modified: 2026-09-19 02:23 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-07-02 15:27:22 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A security vulnerability has been detected in Open Asset Import Library Assimp up to 5.4.3. Affected by this vulnerability is the function Assimp::SceneCombiner::Copy of the file code/Common/SceneCombiner.cpp of the component Model File Handler. Such manipulation of the argument width/height leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. This and similar defects are tracked and handled via issue #6128.

Comment 1 Aoife Moloney 2026-08-17 15:13:25 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.

Comment 2 Fedora Update System 2026-09-18 22:00:28 UTC
FEDORA-2026-2d7847f75c (assimp-6.0.5-5.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-2d7847f75c

Comment 3 Fedora Update System 2026-09-18 22:00:29 UTC
FEDORA-2026-492ca43634 (assimp-6.0.5-5.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-492ca43634

Comment 4 Fedora Update System 2026-09-18 22:00:30 UTC
FEDORA-2026-37c96a4d1a (assimp-6.0.5-5.fc45) has been submitted as an update to Fedora 45.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-37c96a4d1a

Comment 5 Fedora Update System 2026-09-19 01:40:32 UTC
FEDORA-2026-37c96a4d1a has been pushed to the Fedora 45 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-37c96a4d1a`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-37c96a4d1a

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 6 Fedora Update System 2026-09-19 02:19:26 UTC
FEDORA-2026-492ca43634 has been pushed to the Fedora 44 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-492ca43634`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-492ca43634

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2026-09-19 02:23:11 UTC
FEDORA-2026-2d7847f75c has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-2d7847f75c`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-2d7847f75c

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.


Note You need to log in before you can comment on or make changes to this bug.