Out-of-Bounds Read in Assimp's Half-Life 1 MDL Loader
CVE-2026-10233
Key Information:
Badges
What is CVE-2026-10233?
A security vulnerability has been identified in the Assimp library's Half-Life 1 MDL Loader component, specifically within the HL1MDLLoader::read_sequence_infos function. This flaw enables an out-of-bounds read due to improper handling of the aiString argument. As a consequence, an attacker could exploit this vulnerability through local means, potentially compromising system integrity. This issue has been publicly disclosed, emphasizing the need for immediate remediation efforts.
Affected Version(s)
Assimp 6.0.0
Assimp 6.0.1
Assimp 6.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
