Back Linuxsecurity Fedora 42 Assimp Critical Heap Overflow Fix CVE-2025-11277 2026
Assimp, the Open Asset Import Library, is a free library to import various well-known 3D model formats into applications. Assimp aims to provide a full asset conversion pipeline for use in game engines and real-time rendering systems, but is not limited to these applications. Update Information : Backport fix for CVE-2025-11277.
Assimp, the Open Asset Import Library, is a free library to import
various well-known 3D model formats into applications. Assimp aims
to provide a full asset conversion pipeline for use in game
engines and real-time rendering systems, but is not limited
to these applications.
Backport fix for CVE-2025-11277.
* Tue Jan 13 2026 Sandro Mani - 5.3.1-6 - Backport fix for CVE-2025-11277
* Tue Jan 13 2026 Sandro Mani - 5.3.1-6 - Backport fix for CVE-2025-11277
[ 1 ] Bug #2401927 - CVE-2025-11277 assimp: Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflow [fedora-42]
[ 1 ] Bug #2401927 - CVE-2025-11277 assimp: Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflow [fedora-42]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7069f6c1c8' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
