The vendor explicitly identifies these products as affected by this CVE.
- qt6-qtquick3d as a component of Red Hat Enterprise Linux 10
- qt6-qtquick3d-devel as a component of Red Hat Enterprise Linux 10
- qt6-qtquick3d-examples as a component of Red Hat Enterprise Linux 10
- qt6-qtquick3d.src as a component of Red Hat Enterprise Linux 10
- qt5-qt3d as a component of Red Hat Enterprise Linux 9
- qt5-qt3d-devel as a component of Red Hat Enterprise Linux 9
- qt5-qt3d-examples as a component of Red Hat Enterprise Linux 9
- qt5-qt3d.src as a component of Red Hat Enterprise Linux 9
- Summary
- A flaw was found in Open Asset Import Library Assimp. A remote attacker could exploit a heap-based buffer overflow vulnerability, which occurs when a program writes more data to a memory block than it was intended to hold. This specific flaw exists within the Assimp::Compression::decompressBlock function during file compression decompression. By sending a specially crafted input, an attacker could potentially cause the application to crash (denial of service), disclose sensitive information, or execute arbitrary code.
- Remediation
- To mitigate this vulnerability, avoid processing untrusted or unverified 3D model files with applications that utilize the Assimp library. As this flaw requires user interaction to trigger, exercising caution with the source of 3D assets can reduce exposure. No direct configuration or operational control exists to disable the vulnerable decompression functionality without impacting the core features of the library.
