CVE-2025-2912

Name
CVE-2025-2912
Description
A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://github.com/HDFGroup/hdf5/issues/5370
signature https://vuldb.com/?ctiid.301885
vdb-entry https://vuldb.com/?id.301885
third-party-advisory https://vuldb.com/?submit.519966

Match rules

CPE URI Source package Min version Max version
hdf5 == 1.14.0 == 1.14.0
hdf5 == 1.14.1 == 1.14.1
hdf5 == 1.14.2 == 1.14.2
hdf5 == 1.14.3 == 1.14.3
hdf5 == 1.14.4 == 1.14.4
hdf5 == 1.14.5 == 1.14.5
hdf5 == 1.14.6 == 1.14.6
cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* hdf5 >= None < 1.14.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hdf5 edge-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
hdf5 3.22-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable