CVE-2025-2151
published 2025-03-10CVE-2025-2151: A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the…
PriorityP355high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.55%
42.1th percentile
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| assimp | assimp | — | — |
| assimp | assimp | >= 0 < 6.0.2+ds-1 | 6.0.2+ds-1 |
| debian | assimp | < assimp 6.0.2+ds-1 (forky) | assimp 6.0.2+ds-1 (forky) |
| linux | linux_kernel | >= 2.6.12 < 5.4.301 | 5.4.301 |
| linux | linux_kernel | >= 5.11.0 < 5.15.196 | 5.15.196 |
| linux | linux_kernel | >= 5.16.0 < 6.1.158 | 6.1.158 |
| linux | linux_kernel | >= 5.5.0 < 5.10.246 | 5.10.246 |
| linux | linux_kernel | >= 6.13.0 < 6.17.6 | 6.17.6 |
| linux | linux_kernel | >= 6.2.0 < 6.6.115 | 6.6.115 |
| linux | linux_kernel | >= 6.7.0 < 6.12.56 | 6.12.56 |
| open_asset_import_library | assimp | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv5.3MEDIUM
vendor_debian5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
osv·2025-12-04
CVE-2025-40243 hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
In the Linux kernel, the following vulnerability has been resolved:
hfs: fix KMSAN uninit-value issue in hfs_find_set_zero_bits()
The syzbot reported issue in hfs_find_set_zero_bits():
BUG: KMSAN: uninit-value in hfs_find_set_zero_bits+0x74d/0xb60 fs/hfs/bitmap.c:45
hfs_find_set_zero_bits+0x74d/0xb60 fs/hfs/bitmap.c:45
hfs_vbm_search_free+0x13c/0x5b0 fs/hfs/bitmap.c:151
hfs_extend_file+0x6a5/0x1b00 fs/hfs/extent.c:408
hfs_get_block+0x435/0x1150 fs/hfs/extent.c:353
__block_write_begin_int+0xa76/0x3030 fs/buffer.c:2151
block_write_begin fs/buffer.c:2262 [inline]
cont_write_begin+0x10e1/0x1bc0 fs/buffer.c:2601
hfs_write_begin+0x85/0x130 fs/hfs/inode.c:52
cont_expand_zero fs/buffer.c:2528 [inline]
cont_write_begin+0x35a/0x1bc0 f
GHSA
GHSA-rrc2-m8v6-jh7q: A vulnerability classified as critical was found in Open Asset Import Library Assimp 5
ghsa_unreviewed·2025-03-10
CVE-2025-2151 [MEDIUM] CWE-119 GHSA-rrc2-m8v6-jh7q: A vulnerability classified as critical was found in Open Asset Import Library Assimp 5
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
OSV
CVE-2025-2151: A vulnerability classified as critical was found in Open Asset Import Library Assimp 5
osv·2025-03-10·CVSS 5.3
CVE-2025-2151 [MEDIUM] CVE-2025-2151: A vulnerability classified as critical was found in Open Asset Import Library Assimp 5
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Debian
CVE-2025-2151: assimp - A vulnerability classified as critical was found in Open Asset Import Library As...
vendor_debian·2025·CVSS 5.3
CVE-2025-2151 [MEDIUM] CVE-2025-2151: assimp - A vulnerability classified as critical was found in Open Asset Import Library As...
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 6.0.2+ds-1)
sid: resolved (fixed in 6.0.2+ds-1)
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/assimp/assimp/issues/6016https://github.com/assimp/assimp/issues/6026https://github.com/sae-as-me/Crashes/raw/refs/heads/main/assimp/assimp_crash_1https://vuldb.com/?ctiid.299062https://vuldb.com/?id.299062https://vuldb.com/?submit.510582https://github.com/assimp/assimp/issues/6016https://github.com/assimp/assimp/issues/6026
2025-03-10
Published