Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23385 | MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput |
Github GHSA |
GHSA-7qw8-3vmf-gj32 | MaterialX Null Pointer Dereference in MaterialXCore Shader Generation due to Unchecked implGraphOutput |
Wed, 20 Aug 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation materialx |
|
| CPEs | cpe:2.3:a:linuxfoundation:materialx:1.39.2:-:*:*:*:*:*:* | |
| Vendors & Products |
Linuxfoundation
Linuxfoundation materialx |
|
| Metrics |
cvssV3_1
|
Fri, 01 Aug 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 Aug 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In version 1.39.2, when parsing shader nodes in a MTLX file, the MaterialXCore code accesses a potentially null pointer, which can lead to crashes with maliciously crafted files. An attacker could intentionally crash a target program that uses MaterialX by sending a malicious MTLX file. This is fixed in version 1.39.3. | |
| Title | MaterialX is Vulnerable to NULL Pointer Dereference due to Unchecked implGraphOutput | |
| Weaknesses | CWE-476 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-01T18:16:36.719Z
Reserved: 2025-06-24T03:50:36.796Z
Link: CVE-2025-53011
Updated: 2025-08-01T18:16:29.050Z
Status : Analyzed
Published: 2025-08-01T18:15:54.827
Modified: 2025-08-20T21:24:15.683
Link: CVE-2025-53011
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA