Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-19968

CVE-2026-19968: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium4.3

    Medium [CVE-2026-19968] Denial of service via heap-based buffer overflow in 3DGS MDL7 Model Parser

    CVE-2026-19968Source published Source updated

    A weakness has been identified in Open Asset Import Library Assimp 17c12da. The affected element is the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model Parser. Executing a manipulation can lead to heap-based buffer overflow. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. This patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a patch is advised to resolve this issue. A remote attacker could exploit a heap-based buffer overflow vulnerability in the `ReadFaces_3DGS_MDL7` function of the 3DGS MDL7 Model Parser by providing a specially crafted 3DGS MDL7 model file. This could lead to a denial of service. Exploitation requires a…

    Affected products in this advisory
    • Red Hat Enterprise Linux 10
    • Red Hat Enterprise Linux 9
    • Red Hat package: qt6-qtquick3d
    • Red Hat package: qt5-qt3d
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    No fixed-version detail extracted. This does not mean no fix exists.
    Mitigation guidance
    • To reduce the risk of exploitation, avoid processing untrusted 3DGS MDL7 model files with applications that use the Assimp library. Limiting the handling of such files to trusted sources is advised.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery