CVE-2025-2924

Name
CVE-2025-2924
Description
A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HL__fl_deserialize of the file src/H5HLcache.c. The manipulation of the argument free_block leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://github.com/HDFGroup/hdf5/issues/5382
signature https://vuldb.com/?ctiid.301899
vdb-entry https://vuldb.com/?id.301899
third-party-advisory https://vuldb.com/?submit.521170

Match rules

CPE URI Source package Min version Max version
hdf5 == 1.14.0 == 1.14.0
hdf5 == 1.14.1 == 1.14.1
hdf5 == 1.14.2 == 1.14.2
hdf5 == 1.14.3 == 1.14.3
hdf5 == 1.14.4 == 1.14.4
hdf5 == 1.14.5 == 1.14.5
hdf5 == 1.14.6 == 1.14.6
cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* hdf5 >= None <= 1.14.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hdf5 edge-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
hdf5 3.22-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable