Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 470
Alerts This Week
Warning Icon 1 470

Fedora 42 Assimp Critical Heap Overflow Fix CVE-2025-11277 2026-7069f6c1c8

fedora
Calendar Grey January 28, 2026
Scroller Fedora
Fix for critical heap overflow in Assimp library affects Fedora 42. Important update for security.
Backport fix for CVE-2025-11277.

Summary

Assimp, the Open Asset Import Library, is a free library to import

various well-known 3D model formats into applications. Assimp aims

to provide a full asset conversion pipeline for use in game

engines and real-time rendering systems, but is not limited

to these applications.

Update Information:

Backport fix for CVE-2025-11277.

Change Log

* Tue Jan 13 2026 Sandro Mani - 5.3.1-6 - Backport fix for CVE-2025-11277

References


[ 1 ] Bug #2401927 - CVE-2025-11277 assimp: Open Asset Import Library Assimp Q3DLoader.cpp InternReadFile heap-based overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2401927

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7069f6c1c8' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: assimp
Product: Fedora 42
Version: 5.3.1
Release: 6.fc42
Summary: Library to import various 3D model formats into applications

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.