gpp_maybe
Security update for assimp
SUSE-SLES-16.0-1163
This update for assimp fixes the following issues - CVE-2025-11277: large mWidth and mHeight dimensions can lead to integer overflow and a heap-based buffer overflow (bsc#1251019). - CVE-2026-10197: NULL pointer dereference in ImportEmbeddedTextures when mimeType lacks '/' (bsc#1266996). - CVE-2026-10199: NULL pointer dereference in glTF2::LazyDict::operator[] due to unchecked node access in ImportAnimations (bsc#1266998). - CVE-2026-10200: [glTF] Heap-buffer-overflow in CopyValue() when parsing invalid 4x4 matrix with insufficient data (bsc#1266999). - CVE-2026-10232: heap use-after-free in aiNode::~aiNode due to invalid node tree when processing malformed ASE files (bsc#1267037).
-
Release DateJul 6 2026
-
ReferencesBugzilla: 1251019, 1266996, 1266998, 1266999, 1267037
CVEs: CVE-2025-11277, CVE-2026-10197, CVE-2026-10199, CVE-2026-10200, CVE-2026-10232 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Server 16.0 aarch64
-
Packageslibassimp5
Library to load and process 3D scenes from various data formats5.4.3-160000.4.1 lock rpm
SUSE Linux Enterprise Server 16.0 ppc64le
-
Packageslibassimp5
Library to load and process 3D scenes from various data formats5.4.3-160000.4.1 lock rpm
SUSE Linux Enterprise Server 16.0 s390x
-
Packageslibassimp5
Library to load and process 3D scenes from various data formats5.4.3-160000.4.1 lock rpm
SUSE Linux Enterprise Server 16.0 x86_64
-
Packageslibassimp5
Library to load and process 3D scenes from various data formats5.4.3-160000.4.1 lock rpm
SUSE Linux Enterprise Server for SAP applications 16.0 ppc64le
-
Packageslibassimp5
Library to load and process 3D scenes from various data formats5.4.3-160000.4.1 lock rpm
SUSE Linux Enterprise Server for SAP applications 16.0 x86_64
-
Packageslibassimp5
Library to load and process 3D scenes from various data formats5.4.3-160000.4.1 lock rpm