CVE-2026-10199
Publication date 31 May 2026
Last updated 6 June 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A vulnerability has been found in Assimp up to 6.0.4. Affected by this issue is the function glTF2::LazyDict in the library glTF2Asset.h. Such manipulation of the argument operator[] leads to null pointer dereference. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The name of the patch is d24b85319bd70c65883a2b96613e07e23fb95981. It is best practice to apply a patch to resolve this issue.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| assimp | 26.04 LTS resolute |
Needs evaluation
|
| 25.10 questing |
Needs evaluation
|
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | Low |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-10199
- https://github.com/assimp/assimp/issues/6611
- https://github.com/assimp/assimp/pull/6646
- https://github.com/assimp/assimp/commit/d24b85319bd70c65883a2b96613e07e23fb95981
- https://github.com/assimp/assimp/
- https://github.com/user-attachments/files/27194148/poc.zip
- https://vuldb.com/cve/CVE-2026-10199
- https://vuldb.com/submit/821179
- https://vuldb.com/vuln/367479
- https://vuldb.com/vuln/367479/cti