Back

MEDIUM

Assimp TF File glTF2Importer.cpp ImportEmbeddedTextures null pointer dereference

Published May 31, 2026

Description

A vulnerability was detected in Assimp up to 6.0.4. Affected is the function glTF2Importer::ImportEmbeddedTextures in the library code/AssetLib/glTF2/glTF2Importer.cpp of the component TF File Handler. The manipulation results in null pointer dereference. The attack is only possible with local access. The exploit is now public and may be used. It is advisable to implement a patch to correct this issue. The pull request to fix this issue awaits acceptance.

Affected products

Remediation

Red Hat statement

This Moderate impact null pointer dereference vulnerability in Assimp's glTF2Importer requires local system access to trigger a Denial of Service. While the flaw can make an application unavailable, its local nature limits the overall risk to Red Hat products.

Red Hat mitigation

Users should avoid processing untrusted glTF2 files with applications that rely on the Assimp library. This vulnerability requires local access and the processing of a specially crafted file to trigger the null pointer dereference, leading to a denial of service.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 31, 2026
Updated Jun 1, 2026
Reserved May 31, 2026
CISA Vulnrichment
Updated Jun 1, 2026
NVD
Status Deferred
Modified Jul 22, 2026
Red Hat
Severity Moderate
Public date May 31, 2026