Skip to content
VulniPulse
Advisory severityMedium5.6Red Hat Linux

Medium [CVE-2026-19999] Remote buffer overflow allows information disclosure or denial of service

This medium-severity Red Hat Linux advisory covers CVE-2026-19999.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-19999 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Bone Transformation Key Parser.

The manipulation of the argument transmatrix_count/pcBoneTransforms leads to buffer overflow. It is possible to initiate the attack remotely.

The exploit has been disclosed publicly and may be used. The identifier of the patch is 50d767984e78d51b53e2020fdf0967fd624bc377.

It is recommended to apply a patch to fix this issue. A buffer overflow in Assimp's ParseBoneTrafoKeys_3DGS_MDL7 function allows a remote attacker to cause a denial of service or potentially access sensitive information by tricking a user into loading a maliciously crafted 3DGS MDL7 file.

Red Hat products are not affected because their builds exclude the vulnerable code. Red Hat severity: Moderate — CVSS 5.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H).

Weakness: CWE-120. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9 as not affected.

Affected versions

No affected-version range was extracted from the source record. The vendor advisory is authoritative — check it before change work.

Official advisory · high-confidence parse· fetched 24 days ago·verify at source

Fixed versions

No fixed release is recorded yet. That does not prove no patch exists — confirm against the vendor advisory.

Official advisory · high-confidence parse· fetched 24 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, avoid processing untrusted 3DGS MDL7 files with applications that use the Assimp library. Do not import untrusted 3D GameStudio MDL7 (.mdl) files with Assimp or Assimp-based importers. Allowlist only trusted model files and formats the application needs.

Official advisory · high-confidence parse· fetched 24 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.