PT-2026-45273 · Debian+2 · Assimp

·

CVE-2026-10229

·

Published

2026-06-01

·

Updated

2026-06-01

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Assimp versions prior to 6.0.5
Description A heap-based buffer overflow occurs in the Half-Life 1 MDL Loader component. The issue is located within the read meshes() function of the HL1MDLLoader.cpp file. This flaw allows for local execution of an attack.
Recommendations Update to version 6.0.5 or later. As a temporary workaround, restrict the use of the Half-Life 1 MDL Loader component.

Exploit

Fix

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10229

Affected Products

Assimp