{"id":"openSUSE-SU-2026:21242-1","summary":"Security update for assimp","details":"This update for assimp fixes the following issues\n\n- CVE-2025-11277: large mWidth and mHeight dimensions can lead to integer overflow and a heap-based buffer overflow\n  (bsc#1251019).\n- CVE-2026-10197: NULL pointer dereference in ImportEmbeddedTextures when mimeType lacks '/' (bsc#1266996).\n- CVE-2026-10199: NULL pointer dereference in glTF2::LazyDict::operator[] due to unchecked node access in\n  ImportAnimations (bsc#1266998).\n- CVE-2026-10200: [glTF] Heap-buffer-overflow in CopyValue() when parsing invalid 4x4 matrix with insufficient data\n  (bsc#1266999).\n- CVE-2026-10232: heap use-after-free in aiNode::~aiNode due to invalid node tree when processing malformed ASE files\n  (bsc#1267037).\n","modified":"2026-07-09T10:00:10.922199803Z","published":"2026-07-06T14:23:04Z","related":["CVE-2025-11277","CVE-2026-10197","CVE-2026-10199","CVE-2026-10200","CVE-2026-10232"],"upstream":["CVE-2025-11277","CVE-2026-10197","CVE-2026-10199","CVE-2026-10200","CVE-2026-10232"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1251019"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266996"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266998"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266999"},{"type":"REPORT","url":"https://bugzilla.suse.com/1267037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-11277"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-10197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-10199"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-10200"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-10232"}],"affected":[{"package":{"name":"assimp","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/assimp&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.3-160000.4.1"}]}],"ecosystem_specific":{"binaries":[{"assimp-devel":"5.4.3-160000.4.1","libassimp5":"5.4.3-160000.4.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21242-1.json"}}],"schema_version":"1.7.5"}