CVE-2026-19967

medium Red Hat
CVSS v3 Base Score
6.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
Low
Integrity
Low
Availability
Low
Published: August 17, 2026 (20 days ago)
Last Modified: August 17, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in Open Asset Import Library Assimp. A remote attacker could exploit a heap-based buffer overflow vulnerability, which occurs when a program writes more data to a memory block than it was intended to hold. This specific flaw exists within the Assimp::Compression::decompressBlock function during file compression decompression. By sending a specially crafted input, an attacker could potentially cause the application to crash (denial of service), disclose sensitive information, or execute arbitrary code.

CWE

CWE-120

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 9

References