Sceawere
Vulnerability Detail
CVE-2026-108573UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Assimp PLY Out-of-Bounds Read
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 3h ago
- Vendor
- Open Asset Import Library
- Product
- Assimp
- Attack Type
- Out-of-Bounds Read
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in Open Asset Import Library Assimp up to 6.0.5. Affected by this vulnerability is the function IOStreamBuffer::getNextBlock of the component PLY File Handler. Performing a manipulation results in out-of-bounds read. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-11T12:16:52.783Z",
"pubdate": "2026-10-11T12:16:52.783Z",
"executiveSummary": "A critical out-of-bounds read vulnerability has been identified in the Open Asset Import Library (Assimp) versions up to 6.0.5. The vulnerability resides within the PLY file handler component, specifically inside the IOStreamBuffer::getNextBlock function.\nThis flaw allows a remote attacker to trigger an out-of-bounds memory read by providing a maliciously crafted PLY file. The vulnerability poses a significant risk to applications utilizing Assimp for 3D model processing, as it could lead to information disclosure or potential application crashes due to memory access violations.\nThe issue stems from improper bounds checking when handling input streams, enabling an attacker to read data beyond the intended buffer limits. Successful exploitation can be achieved remotely without requiring specific authentication or high-level privileges from the user, provided they can influence the input file processed by the application. Given the lack of response from the vendor, users are advised to implement strict input validation or sandboxing measures to mitigate potential exploitation attempts.",
"technicalDetails": "The vulnerability is located within the IOStreamBuffer::getNextBlock function, which is a component of the PLY file handling logic in Assimp. The root cause of this vulnerability is an insufficient validation of buffer offsets and block size parameters during the parsing of PLY files. When the library processes the structure of a PLY file, the IOStreamBuffer component is responsible for reading data blocks into memory buffers. If the file headers or block metadata specify values that mismatch the actual available stream data, the internal pointer arithmetic within getNextBlock fails to enforce strict boundaries.\nAn attacker can exploit this by injecting specifically crafted values into the PLY header, forcing the IOStreamBuffer to calculate an address outside of the allocated memory range. When getNextBlock proceeds to retrieve the next block, it performs a read operation at this unauthorized memory address. Because the function lacks adequate boundary constraints, it continues to return contents from adjacent memory, leading to an out-of-bounds read.\nThe attack flow proceeds as follows: First, the attacker delivers a malicious PLY file to the target system, which is subsequently parsed by the Assimp library. As the parser reaches the IOStreamBuffer::getNextBlock function, the logic consumes the malformed input that misleads the function's pointer tracking. The function then attempts to copy or return data from the calculated out-of-bounds location. This sequence requires no authentication or special user privileges; the exploitation is contingent solely on the library's ingestion of the hostile file.\nThe impact of this vulnerability ranges from sensitive information leakage—where adjacent heap memory might be exposed to the attacker through the application's output—to a denial-of-service (DoS) condition caused by the segmentation fault triggered when the read operation attempts to access unmapped or protected memory segments. Given that Assimp is often integrated into media players, rendering engines, and game development environments, the remote exploitation vector is particularly dangerous as it could lead to the compromise of data processed by these applications."
}