Back

MEDIUM

Assimp ASE File scene.cpp ~aiNode use after free

Published Jun 1, 2026

Description

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.

Affected products

Remediation

Red Hat statement

This Moderate impact use-after-free flaw in Assimp's ASE File Parser component allows a local attacker to cause information disclosure, data corruption, or a denial of service. Exploitation requires the attacker to have local access and manipulate specific 3D model data, limiting the attack vector to scenarios where untrusted files are processed.

Red Hat mitigation

To reduce exposure, avoid processing untrusted 3D model files, especially those in the ASE format, with applications that use the Assimp library. If processing untrusted input is unavoidable, consider sandboxing the affected applications to limit potential impact. This operational control may affect functionality if applications depend on processing untrusted ASE files.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Jun 1, 2026
Updated Jun 2, 2026
Reserved May 31, 2026
CISA Vulnrichment
Updated Jun 2, 2026
NVD
Status Deferred
Modified Jul 22, 2026
Red Hat
Severity Moderate
Public date Jun 1, 2026
ENISA EUVD
Assigner VulDB
Published Jun 1, 2026
Updated Jun 2, 2026
Exploited since n/a
EUVD-2026-33565