Back

MEDIUM

HDF5 H5Omessage.c H5O_msg_flush heap-based overflow

Published Mar 28, 2025

Description

A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 28, 2025
Updated Jul 24, 2025
Reserved Mar 28, 2025
CISA Vulnrichment
Updated Mar 28, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 28, 2025
ENISA EUVD
Assigner VulDB
Published Mar 28, 2025
Updated Jul 24, 2025
Exploited since n/a
EUVD-2025-8636