CVE-2024-48425: Assimp

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference.

Affected products

  • Assimp Assimp: version 5.4.3 only

Published 2024-10-24. Last modified 2026-06-17.