Bug 2483759 (CVE-2026-10230) - CVE-2026-10230 assimp: Assimp: Local heap-based buffer overflow in Half-Life 1 MDL Loader
Summary: CVE-2026-10230 assimp: Assimp: Local heap-based buffer overflow in Half-Life ...
Keywords:
Status: NEW
Alias: CVE-2026-10230
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-06-01 15:29 UTC by Keith Grant
Modified: 2026-07-18 08:29 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Keith Grant 2026-06-01 15:29:05 UTC
A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The project tagged the reported issue as bug.


Note You need to log in before you can comment on or make changes to this bug.