CVE Vulnerabilities

CVE-2025-4605

Memory Allocation with Excessive Size Value

Published: Jun 11, 2025 | Modified: Jul 30, 2025
CVSS 3.x
6.6
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.

Weakness

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

Affected Software

Name Vendor Start Version End Version
Maya Autodesk 2025 (including) 2025.3.1 (excluding)
Universal_scene_description Autodesk 0.10 (including) 0.10 (including)
Universal_scene_description Autodesk 0.31.0 (including) 0.31.0 (including)

Potential Mitigations

References