Heap-Based Buffer Overflow in Assimp's Half-Life 1 MDL Loader
CVE-2026-10230
Key Information:
Badges
What is CVE-2026-10230?
A vulnerability exists in the Assimp Half-Life 1 MDL Loader within the read_animations function, located in HL1MDLLoader.cpp. This issue can lead to a heap-based buffer overflow when manipulated, which requires local access to exploit. The reported vulnerability has been publicly disclosed, and remediation efforts are necessary to mitigate potential risks. Users and administrators should ensure they are using the latest versions of the software to reduce exposure.
Affected Version(s)
Assimp 6.0.0
Assimp 6.0.1
Assimp 6.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
