CVE-2025-2926

Name
CVE-2025-2926
Description
A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
exploit https://github.com/HDFGroup/hdf5/issues/5384
signature https://vuldb.com/?ctiid.301901
vdb-entry https://vuldb.com/?id.301901
third-party-advisory https://vuldb.com/?submit.521246

Match rules

CPE URI Source package Min version Max version
hdf5 == 1.14.0 == 1.14.0
hdf5 == 1.14.1 == 1.14.1
hdf5 == 1.14.2 == 1.14.2
hdf5 == 1.14.3 == 1.14.3
hdf5 == 1.14.4 == 1.14.4
hdf5 == 1.14.5 == 1.14.5
hdf5 == 1.14.6 == 1.14.6
cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* hdf5 >= None <= 1.14.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hdf5 edge-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
hdf5 3.22-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable