bullet3 VHACD utility: stack-based buffer overflow in OFF parser (LoadOFF)
Vulnerability Description
Stack-based buffer overflow in LoadOFF in bulletphysics bullet3 before 3.26 on all platforms allows remote attackers to execute arbitrary code via a crafted OFF file with an overlong initial token processed by the VHACD test utility or invoked indirectly through PyBullet's vhacd function.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8854
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Simcha Kosman
Affected Vendor
bulletphysics
View all reports →