#1145890 assimp: CVE-2026-19967 CVE-2026-19968 CVE-2026-19969 CVE-2026-19970 CVE-2026-19999

Package:
src:assimp
Source:
src:assimp
Submitter:
Salvatore Bonaccorso
Date:
2026-08-27 14:41:03 UTC
Severity:
normal
Tags:
#1145890#5
Date:
2026-08-27 14:40:35 UTC
From:
To:
Hi,

The following vulnerabilities were published for assimp.

CVE-2026-19967[0]:
| A security flaw has been discovered in Open Asset Import Library
| Assimp 17c12da. Impacted is the function
| Assimp::Compression::decompressBlock of the file
| code/Common/Compression.cpp of the component File Parser. Performing
| a manipulation results in heap-based buffer overflow. The attack may
| be initiated remotely. The exploit has been released to the public
| and may be used for attacks. The project was informed of the problem
| early through an issue report but has not responded yet.


CVE-2026-19968[1]:
| A weakness has been identified in Open Asset Import Library Assimp
| 17c12da. The affected element is the function
| Assimp::MDLImporter::ReadFaces_3DGS_MDL7 in the library
| code/AssetLib/LWO/LWOLoader.h of the component 3DGS MDL7 Model
| Parser. Executing a manipulation can lead to heap-based buffer
| overflow. The attack may be launched remotely. The exploit has been
| made available to the public and could be used for attacks. This
| patch is called ee77bb09a42a49843ac85ef64c14d2328b251df1. Applying a
| patch is advised to resolve this issue.


CVE-2026-19969[2]:
| A security vulnerability has been detected in Open Asset Import
| Library Assimp 17c12da. The impacted element is the function
| Assimp::MDLImporter::GenerateOutputMeshes_3DGS_MDL7 of the file
| code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Model
| Output Mesh Generator. The manipulation leads to buffer overflow.
| Remote exploitation of the attack is possible. The exploit has been
| disclosed publicly and may be used. The project was informed of the
| problem early through an issue report but has not responded yet.


CVE-2026-19970[3]:
| A vulnerability was detected in Open Asset Import Library Assimp
| 17c12da. This affects the function
| Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 of the file
| code/AssetLib/MDL/MDLLoader.cpp of the component Node Parser. The
| manipulation of the argument bones_num results in heap-based buffer
| overflow. The attack can be executed remotely. The exploit is now
| public and may be used. The project was informed of the problem
| early through an issue report but has not responded yet.


CVE-2026-19999[4]:
| A security vulnerability has been detected in Open Asset Import
| Library Assimp Assimp 17c12da. The affected element is the function
| Assimp::MDLImporter::ParseBoneTrafoKeys_3DGS_MDL7 of the file
| code/AssetLib/MDL/MDLLoader.cpp of the component 3DGS MDL7 Bone
| Transformation Key Parser. The manipulation of the argument
| transmatrix_count/pcBoneTransforms leads to buffer overflow. It is
| possible to initiate the attack remotely. The exploit has been
| disclosed publicly and may be used. The identifier of the patch is
| 50d767984e78d51b53e2020fdf0967fd624bc377. It is recommended to apply
| a patch to fix this issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19967
https://www.cve.org/CVERecord?id=CVE-2026-19967
[1] https://security-tracker.debian.org/tracker/CVE-2026-19968
https://www.cve.org/CVERecord?id=CVE-2026-19968
[2] https://security-tracker.debian.org/tracker/CVE-2026-19969
https://www.cve.org/CVERecord?id=CVE-2026-19969
[3] https://security-tracker.debian.org/tracker/CVE-2026-19970
https://www.cve.org/CVERecord?id=CVE-2026-19970
[4] https://security-tracker.debian.org/tracker/CVE-2026-19999
https://www.cve.org/CVERecord?id=CVE-2026-19999

Regards,
Salvatore