Assimp ASE File scene.cpp ~aiNode use after free
Published Jun 1, 2026
4.8
MEDIUMCVSS 4.0
EPSS 0.11%
Description
A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.
Affected products
-
- Version 6.0.0StatusaffectedConstraints-
- Version 6.0.1StatusaffectedConstraints-
- Version 6.0.2StatusaffectedConstraints-
- Version 6.0.3StatusaffectedConstraints-
- Version 6.0.4StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat Enterprise Linux 10
qt6-qtquick3d
Fix deferred
Red Hat Enterprise Linux 9
qt5-qt3d
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | qt6-qtquick3d | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | qt5-qt3d | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This Moderate impact use-after-free flaw in Assimp's ASE File Parser component allows a local attacker to cause information disclosure, data corruption, or a denial of service. Exploitation requires the attacker to have local access and manipulate specific 3D model data, limiting the attack vector to scenarios where untrusted files are processed.
Red Hat mitigation
To reduce exposure, avoid processing untrusted 3D model files, especially those in the ASE format, with applications that use the Assimp library. If processing untrusted input is unavoidable, consider sandboxing the affected applications to limit potential impact. This operational control may affect functionality if applications depend on processing untrusted ASE files.
References (12)
- https://access.redhat.com/security/cve/CVE-2026-10232 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2486783 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33565 Advisory
- https://github.com/assimp/assimp/ product
- https://github.com/assimp/assimp/issues/6617 issue-tracking
- https://github.com/user-attachments/files/27200601/poc.zip exploit
- https://nvd.nist.gov/vuln/detail/CVE-2026-10232
- https://vuldb.com/cve/CVE-2026-10232 third-party-advisory
- https://vuldb.com/submit/821192 third-party-advisory
- https://vuldb.com/vuln/367511 vdb-entrytechnical-description
- https://vuldb.com/vuln/367511/cti signaturepermissions-required
- https://www.cve.org/CVERecord?id=CVE-2026-10232
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-10232 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2486783 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33565 | Advisory | |
| https://github.com/assimp/assimp/ | product | |
| https://github.com/assimp/assimp/issues/6617 | issue-tracking | |
| https://github.com/user-attachments/files/27200601/poc.zip | exploit | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-10232 | ||
| https://vuldb.com/cve/CVE-2026-10232 | third-party-advisory | |
| https://vuldb.com/submit/821192 | third-party-advisory | |
| https://vuldb.com/vuln/367511 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/367511/cti | signaturepermissions-required | |
| https://www.cve.org/CVERecord?id=CVE-2026-10232 |
Change history (0)
No recorded changes yet.