Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference
Published May 31, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.11%
Description
A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue. The pull request to fix this issue awaits acceptance.
Affected products
-
- Version 6.0.0StatusaffectedConstraints-
- Version 6.0.1StatusaffectedConstraints-
- Version 6.0.2StatusaffectedConstraints-
- Version 6.0.3StatusaffectedConstraints-
- Version 6.0.4StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat Enterprise Linux 10
qt6-qtquick3d
Not affected
Red Hat Enterprise Linux 9
qt5-qt3d
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | qt6-qtquick3d | Not affected | n/a |
| Red Hat Enterprise Linux 9 | qt5-qt3d | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact null pointer dereference vulnerability in Assimp's glTF2Importer requires local system access to trigger a Denial of Service. While the flaw can make an application unavailable, its local nature limits the overall risk to Red Hat products.
Red Hat mitigation
Users should avoid processing untrusted glTF2 files with applications that rely on the Assimp library. This vulnerability requires local access and the processing of a specially crafted file to trigger the null pointer dereference, leading to a denial of service.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
1 other source (NVD) ▾
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
2 other sources (CVE.org, NVD) ▾
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C
AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C
1 other source (NVD) ▾
AV:L/AC:L/Au:S/C:N/I:N/A:P
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jun 1, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Jun–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.11% (0.00115) | 1.40th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.11% (0.00115) | 1.82th | v5 (v2026.06.15) |
| Jun 1, 2026 | 0.01% (0.00013) | 2.15th | v4 (v2025.03.14) |
References (12)
- https://access.redhat.com/security/cve/CVE-2026-10197 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2483755 Issue Tracking
- https://github.com/assimp/assimp/ product
- https://github.com/assimp/assimp/issues/6608 issue-tracking
- https://github.com/assimp/assimp/pull/6645 issue-trackingpatch
- https://github.com/user-attachments/files/27193894/poc.zip exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-10197
- https://vuldb.com/cve/CVE-2026-10197 third-party-advisory
- https://vuldb.com/submit/821177 third-party-advisory
- https://vuldb.com/vuln/367477 vdb-entrytechnical-description
- https://vuldb.com/vuln/367477/cti signaturepermissions-required
- https://www.cve.org/CVERecord?id=CVE-2026-10197
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-10197 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2483755 | Issue Tracking | |
| https://github.com/assimp/assimp/ | product | |
| https://github.com/assimp/assimp/issues/6608 | issue-tracking | |
| https://github.com/assimp/assimp/pull/6645 | issue-trackingpatch | |
| https://github.com/user-attachments/files/27193894/poc.zip | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-10197 | ||
| https://vuldb.com/cve/CVE-2026-10197 | third-party-advisory | |
| https://vuldb.com/submit/821177 | third-party-advisory | |
| https://vuldb.com/vuln/367477 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/367477/cti | signaturepermissions-required | |
| https://www.cve.org/CVERecord?id=CVE-2026-10197 |
Change history (0)
No recorded changes yet.