Back

MEDIUM

Assimp glTF2Asset.h LazyDict null pointer dereference

Published May 31, 2026

Description

A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of the argument operator[] leads to null pointer dereference. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The name of the patch is d24b85319bd70c65883a2b96613e07e23fb95981. It is best practice to apply a patch to resolve this issue.

Affected products

Remediation

Red Hat statement

Moderate: A null pointer dereference flaw was identified in Assimp, affecting the glTF2::LazyDict function. This vulnerability requires local access and could allow an attacker to cause an application crash, leading to a denial of service.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published May 31, 2026
Updated Jun 1, 2026
Reserved May 31, 2026
CISA Vulnrichment
Updated Jun 1, 2026
NVD
Status Deferred
Modified Jul 22, 2026
Red Hat
Severity Moderate
Public date May 31, 2026