Medium [CVE-2026-19999] Remote buffer overflow allows information disclosure or denial of service
This medium-severity Red Hat Linux advisory covers CVE-2026-19999.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Bone Transformation Key Parser.
The manipulation of the argument transmatrix_count/pcBoneTransforms leads to buffer overflow. It is possible to initiate the attack remotely.
The exploit has been disclosed publicly and may be used. The identifier of the patch is 50d767984e78d51b53e2020fdf0967fd624bc377.
It is recommended to apply a patch to fix this issue. A buffer overflow in Assimp's ParseBoneTrafoKeys_3DGS_MDL7 function allows a remote attacker to cause a denial of service or potentially access sensitive information by tricking a user into loading a maliciously crafted 3DGS MDL7 file.
Red Hat products are not affected because their builds exclude the vulnerable code. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H).
Weakness: CWE-120. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9 as not affected.
Affected versions
No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.
Official advisory · high-confidence parse· fetched 24 days ago·verify at source
Fixed versions
No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.
Official advisory · high-confidence parse· fetched 24 days ago·verify at source
Mitigation checklist
- To mitigate this issue, avoid processing untrusted 3DGS MDL7 files with applications that use the Assimp library. Do not import untrusted 3D GameStudio MDL7 (.mdl) files with Assimp or Assimp-based importers. Allowlist only trusted model files and formats the application needs.
Official advisory · high-confidence parse· fetched 24 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.