VDB
Sign up
MEDIUM

GHSA-grjp-54v3-c442

OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability

Quick fix

GHSA-grjp-54v3-c442 — usd-core: upgrade to the fixed version with the command below.

pip install --upgrade 'usd-core>=25.11'

Details

# Patch This is fixed with [commit b953092](https://github.com/PixarAnimationStudios/OpenUSD/commit/b9530922b6a8ea72cd43661226b693fff8abbe4c), with the fix available in OpenUSD 25.11 and onwards.

# Summary We have been advised by Zero Day Initiative that our usage of the USD framework may constitute a Use-After-Free Remote Code Execution Vulnerability. They have sent us the attached file illustrating the issue. Indeed, we see a use after free exception when running the file through our importer with an address sanitizer.

[zdi-23709-poc0.zip](https://github.com/user-attachments/files/17474297/zdi-23709-poc0.zip)

Thanks in advance.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/usd-core
Introduced in: 0Fixed in: 25.11
Fixpip install --upgrade 'usd-core>=25.11'

References