CVE-2025-11017

Severity CVSS v4.0:
MEDIUM
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
26/09/2025
Last modified:
08/10/2025

Description

A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::stream of the file /ogre/OgreMain/src/OgreLogManager.cpp. Performing manipulation of the argument mDefaultLog results in null pointer dereference. The attack must be initiated from a local position. The exploit is now public and may be used.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ogre3d:ogre:*:*:*:*:*:*:*:* 14.4.1 (including)