CVE-2025-6269

Name
CVE-2025-6269
Description
A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5C__reconstruct_cache_entry of the file H5Cimage.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
issue-tracking https://github.com/HDFGroup/hdf5/issues/5579
exploit https://github.com/user-attachments/files/20626503/reproduce.tar.gz
signature https://vuldb.com/?ctiid.313273
vdb-entry https://vuldb.com/?id.313273
third-party-advisory https://vuldb.com/?submit.592587

Match rules

CPE URI Source package Min version Max version
hdf5 == 1.14.0 == 1.14.0
hdf5 == 1.14.1 == 1.14.1
hdf5 == 1.14.2 == 1.14.2
hdf5 == 1.14.3 == 1.14.3
hdf5 == 1.14.4 == 1.14.4
hdf5 == 1.14.5 == 1.14.5
hdf5 == 1.14.6 == 1.14.6
cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* hdf5 >= None <= 1.14.6

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
hdf5 edge-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable
hdf5 3.22-community 1.14.4.2-r1 Holger Jaekel <holger.jaekel@gmx.de> possibly vulnerable