CVE-2026-2653
published 2026-02-18CVE-2026-2653: A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a…
PriorityP348high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.24%
15.3th percentile
A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. It looks like this product is not really maintained anymore.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| admesh_project | admesh | <= 0.98.5 | — |
| admesh_project | admesh | — | — |
| admesh_project | admesh | — | — |
| admesh_project | admesh | — | — |
| admesh_project | admesh | — | — |
| admesh_project | admesh | — | — |
| admesh_project | admesh | — | — |
| debian | admesh | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.3MEDIUMAV:L/AC:L/Au:S/C:P/I:P/A:P
osv4.8MEDIUM
vendor_debian4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2026-2653: admesh - A security flaw has been discovered in admesh up to 0.98.5. This issue affects t...
vendor_debian·2026·CVSS 4.8
CVE-2026-2653 [MEDIUM] CVE-2026-2653: admesh - A security flaw has been discovered in admesh up to 0.98.5. This issue affects t...
A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. It looks like this product is not really maintained anymore.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-vcj6-96x2-26j3: A security flaw has been discovered in admesh up to 0
ghsa_unreviewed·2026-02-18
CVE-2026-2653 [MEDIUM] CWE-119 GHSA-vcj6-96x2-26j3: A security flaw has been discovered in admesh up to 0
A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. It looks like this product is not really maintained anymore.
OSV
CVE-2026-2653: A security flaw has been discovered in admesh up to 0
osv·2026-02-18·CVSS 4.8
CVE-2026-2653 [MEDIUM] CVE-2026-2653: A security flaw has been discovered in admesh up to 0
A security flaw has been discovered in admesh up to 0.98.5. This issue affects the function stl_check_normal_vector of the file src/normals.c. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. It looks like this product is not really maintained anymore.
No detection rules found.
No public exploits indexed.
https://github.com/admesh/admesh/https://github.com/admesh/admesh/issues/65https://github.com/admesh/admesh/issues/65#issuecomment-3804571402https://github.com/user-attachments/files/24878279/id.000035.sig.06.src.000550.time.910126.execs.241742.op.havoc.rep.5.ziphttps://vuldb.com/?ctiid.346450https://vuldb.com/?id.346450https://vuldb.com/?submit.752596
2026-02-18
Published