What is CVE-2026-19970?
A vulnerability was detected in Assimp's MDLLoader.cpp file, within the AddBonesToNodeGraph_3DGS_MDL7 function. Manipulation of the `bones_num` argument leads to a heap-based buffer overflow, potentially causing system instability. Users are advised to update the library.
Azərbaycanca: Bu zəiflik Assimp kitabxanasında MDLLoader.cpp faylındakı AddBonesToNodeGraph_3DGS_MDL7 funksiyasında aşkarlanıb. `bones_num` arqumentinin manipulyasiyası heap-based buffer overflow ilə nəticələnir ki, bu da sistemin dayanıqlığını poza bilər. İstifadəçilərə kitabxananı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which file of the Assimp library was the CVE-2026-19970 vulnerability detected?
The vulnerability was detected in the MDLLoader.cpp file of the Assimp library.
What is the impact of the CVE-2026-19970 vulnerability?
The vulnerability leads to a heap-based buffer overflow, which can cause system instability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.