CVE-2026-82591: Open Asset Import Library Assimp MD5Loader.cpp MakeDataUnique heap-based overflow
A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. The impacted element is the function MD5Importer::MakeDataUnique of the file code/AssetLib/MD5/MD5Loader.cpp. The manipulation of the argument iNewIndex leads to heap-based buffer overflow. The attack can only be performed from a local environment. The identifier of the patch is bf9dabb617c46e5133dac65cca6bff177917afcb. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open Asset Import Library Assimpto a version that resolves this vulnerability.Patch bf9dabb617c46e5133dac65cca6bff177917afcb
Event History
Frequently Asked Questions
Who is realistically exposed to exploitation?
Only local attackers are in scope. Exploitation requires local access and the ability to manipulate the iNewIndex argument reaching MD5Importer::MakeDataUnique.
Which versions are affected?
Assimp versions up to and including 6.0.2 are reported as affected.
What should be done if the installation may be vulnerable?
Apply the patch identified as bf9dabb617c46e5133dac65cca6bff177917afcb. The provided data does not specify an alternative mitigation when patching cannot be performed immediately.