Description
A maliciously crafted .usdc file, when loaded through Autodesk Maya, can force an uncontrolled memory allocation vulnerability. A malicious actor may leverage this vulnerability to cause a denial-of-service (DoS), or cause data corruption.
Problem types
CWE-789 Memory Allocation with Excessive Size Value
Product status
Maya USD 0.31.0 (custom) before Maya USD 0.32.0
Max USD 0.10 (custom) before Max USD 0.11
2025 (custom) before 2025.3.1
References
github.com/Autodesk/maya-usd
github.com/Autodesk/3dsmax-usd
www.autodesk.com/products/autodesk-access/overview
www.autodesk.com/trust/security-advisories/adsk-sa-2025-0011