HDF5 H5Omessage.c H5O_msg_flush heap-based overflow
Published Mar 28, 2025
4.8
MEDIUMCVSS 4.0
EPSS 0.27%
Description
A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Affected products
- Vendor n/a Product HDF5 Defaultn/a
- Version 1.14.0StatusaffectedConstraints-
- Version 1.14.1StatusaffectedConstraints-
- Version 1.14.2StatusaffectedConstraints-
- Version 1.14.3StatusaffectedConstraints-
- Version 1.14.4StatusaffectedConstraints-
- Version 1.14.5StatusaffectedConstraints-
- Version 1.14.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | HDF5 | n/a |
|
No data.
Red Hat Enterprise Linux AI (RHEL AI)
hdf5
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) | hdf5 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-2912 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2355805 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-8636 Advisory
- https://github.com/HDFGroup/hdf5/issues/5370 exploitissue-trackingIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-2912
- https://vuldb.com/?ctiid.301885 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.301885 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.519966 third-party-advisoryThird Party AdvisoryVDB Entry
- https://www.cve.org/CVERecord?id=CVE-2025-2912
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-2912 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2355805 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-8636 | Advisory | |
| https://github.com/HDFGroup/hdf5/issues/5370 | exploitissue-trackingIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-2912 | ||
| https://vuldb.com/?ctiid.301885 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.301885 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.519966 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://www.cve.org/CVERecord?id=CVE-2025-2912 |
Change history (0)
No recorded changes yet.