CVE-2025-6119

Name
CVE-2025-6119
Description
A vulnerability classified as critical has been found in Open Asset Import Library Assimp up to 5.4.3. Affected is the function Assimp::BVHLoader::ReadNodeChannels in the library assimp/code/AssetLib/BVH/BVHLoader.cpp. The manipulation of the argument pNode leads to use after free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/assimp/assimp/issues/6219
issue-tracking https://github.com/assimp/assimp/issues/6219#issuecomment-2945016005
exploit https://github.com/user-attachments/files/20604791/reproduce_2.tar.gz
signature https://vuldb.com/?ctiid.312588
vdb-entry https://vuldb.com/?id.312588
third-party-advisory https://vuldb.com/?submit.591233

Match rules

CPE URI Source package Min version Max version
assimp == 5.4.0 == 5.4.0
assimp == 5.4.1 == 5.4.1
assimp == 5.4.2 == 5.4.2
assimp == 5.4.3 == 5.4.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
assimp edge-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable
assimp 3.22-community 5.4.3-r0 Russ Webber <russ@rw.id.au> possibly vulnerable