Metrics
Affected Vendors & Products
Wed, 20 Aug 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Linuxfoundation
Linuxfoundation materialx |
|
CPEs | cpe:2.3:a:linuxfoundation:materialx:1.39.2:-:*:*:*:*:*:* | |
Vendors & Products |
Linuxfoundation
Linuxfoundation materialx |
|
Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 01 Aug 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, nested imports of MaterialX files can lead to a crash via stack memory exhaustion, due to the lack of a limit on the "import chain" depth. When parsing file imports, recursion is used to process nested files; however, there is no limit imposed to the depth of files that can be parsed by the library. By building a sufficiently deep chain of MaterialX files one referencing the next, it is possible to crash the process using the MaterialX library via stack exhaustion. This is fixed in version 1.39.3. | |
Title | MaterialX's Lack of Import Depth Limit Leads to DoS (Denial-Of-Service) Via Stack Exhaustion | |
Weaknesses | CWE-400 | |
References |
|
|
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-01T19:04:41.209Z
Reserved: 2025-06-24T03:50:36.796Z
Link: CVE-2025-53012

Updated: 2025-08-01T19:04:34.498Z

Status : Analyzed
Published: 2025-08-01T18:15:54.990
Modified: 2025-08-20T21:24:02.853
Link: CVE-2025-53012

No data.

No data.