{"id":"GHSA-grjp-54v3-c442","summary":"OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability","details":"# Patch\nThis is fixed with [commit b953092](https://github.com/PixarAnimationStudios/OpenUSD/commit/b9530922b6a8ea72cd43661226b693fff8abbe4c), with the fix available in OpenUSD 25.11 and onwards.\n\n# Summary\nWe have been advised by Zero Day Initiative that our usage of the USD framework may constitute a Use-After-Free Remote Code Execution Vulnerability. They have sent us the attached file illustrating the issue. Indeed, we see a use after free exception when running the file through our importer with an address sanitizer.\n\n[zdi-23709-poc0.zip](https://github.com/user-attachments/files/17474297/zdi-23709-poc0.zip)\n\nThanks in advance.","modified":"2025-10-29T22:31:30.040308Z","published":"2025-10-29T22:13:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-10-29T22:13:03Z","nvd_published_at":null,"cwe_ids":["CWE-416"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/PixarAnimationStudios/OpenUSD/security/advisories/GHSA-grjp-54v3-c442"},{"type":"WEB","url":"https://github.com/PixarAnimationStudios/OpenUSD/commit/b9530922b6a8ea72cd43661226b693fff8abbe4c"},{"type":"PACKAGE","url":"https://github.com/PixarAnimationStudios/OpenUSD"}],"affected":[{"package":{"name":"usd-core","ecosystem":"PyPI","purl":"pkg:pypi/usd-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.11"}]}],"versions":["20.11","21.11","21.2","21.5","21.8","22.11","22.3","22.5","22.5.post1","22.8","23.11","23.2","23.5","23.8","24.11","24.3","24.5","24.8","25.2","25.2.post1","25.5","25.5.1","25.8"],"database_specific":{"last_known_affected_version_range":"\u003c= 25.08","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-grjp-54v3-c442/GHSA-grjp-54v3-c442.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}