CVE-2025-2914

Name
CVE-2025-2914
Description
A vulnerability classified as problematic has been found in HDF5 up to 1.14.6. This affects the function H5FS__sinfo_Srialize_Sct_cb of the file src/H5FScache.c. The manipulation of the argument sect leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://github.com/HDFGroup/hdf5/issues/5379
signature https://vuldb.com/?ctiid.301887
vdb-entry https://vuldb.com/?id.301887
third-party-advisory https://vuldb.com/?submit.520880

Match rules

CPE URI Source package Min version Max version
hdf5 == 1.14.0 == 1.14.0
hdf5 == 1.14.1 == 1.14.1
hdf5 == 1.14.2 == 1.14.2
hdf5 == 1.14.3 == 1.14.3
hdf5 == 1.14.4 == 1.14.4
hdf5 == 1.14.5 == 1.14.5
hdf5 == 1.14.6 == 1.14.6
cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* hdf5 >= None <= 1.14.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hdf5 edge-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
hdf5 3.22-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable