Alerts This Week
Warning Icon 1 606
Alerts This Week
Warning Icon 1 606

openSUSE Leap 16.0 Assimp Important Buffer Overflow Vuln 2026-20781-1

opensuse
Calendar Grey May 25, 2026
Dist Opensuse Esm H88
Install the openSUSE security update for assimp addressing important issues and enhancing system reliability.
An update that solves 5 vulnerabilities and has 5 bug fixes can now be installed.

Description

This update for assimp fixes the following issues

- CVE-2025-2151: vulnerability affects the function Assimp: GetNextLine in the library ParsingUtils.h (bsc#1239220).

- CVE-2025-2591: division by zero in code/AssetLib/MDL/MDLLoader.cpp (bsc#1239920).

- CVE-2025-2592: heap-based buffer overflow in Assimp: CSMImporter: InternReadFile of code/AssetLib/CSM/CSMLoader.cpp

(bsc#1239916).

- CVE-2025-3015: manipulation of the argument mIndices leads to out-of-bounds read (bsc#1240412).

- CVE-2025-3548: processing of malformed files may leads to an out-of-bounds read and potential application crash

(bsc#1241367).

Patch instructions:

To install this openSUSE security update use the suse recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 16.0

zypper in -t patch openSUSE-Leap-16.0-787=1

Patch

Package List

- openSUSE Leap 16.0:

assimp-devel-5.4.3-160000.3.1

libassimp5-5.4.3-160000.3.1

References

* bsc#1239220

* bsc#1239916

* bsc#1239920

* bsc#1240412

* bsc#1241367

References:

* https://www.suse.com/security/cve/CVE-2025-2151.html

* https://www.suse.com/security/cve/CVE-2025-2591.html

* https://www.suse.com/security/cve/CVE-2025-2592.html

* https://www.suse.com/security/cve/CVE-2025-3015.html

* https://www.suse.com/security/cve/CVE-2025-3548.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:20781-1
Rating: important
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here