CVE-2024-48426: Assimp

Medium severity, CVSS 6.2. EPSS: 0.2% chance of exploitation in the next 30 days.

A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971).

Affected products

  • Assimp Assimp: version 5.4.3 only

Published 2024-10-24. Last modified 2026-06-17.