A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5F_addr_decode_len of the file /hdf5/src/H5Fint.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
References
Link | Resource |
---|---|
https://github.com/HDFGroup/hdf5/issues/5581 | Exploit Issue Tracking Third Party Advisory |
https://github.com/user-attachments/files/20626851/reproduce.tar.gz | Exploit |
https://vuldb.com/?ctiid.313636 | Permissions Required VDB Entry |
https://vuldb.com/?id.313636 | Third Party Advisory VDB Entry |
https://vuldb.com/?submit.592589 | Third Party Advisory VDB Entry |
Configurations
History
26 Jun 2025, 12:25
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Hdfgroup
Hdfgroup hdf5 |
|
References | () https://github.com/HDFGroup/hdf5/issues/5581 - Exploit, Issue Tracking, Third Party Advisory | |
References | () https://github.com/user-attachments/files/20626851/reproduce.tar.gz - Exploit | |
References | () https://vuldb.com/?ctiid.313636 - Permissions Required, VDB Entry | |
References | () https://vuldb.com/?id.313636 - Third Party Advisory, VDB Entry | |
References | () https://vuldb.com/?submit.592589 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:* | |
CWE | CWE-787 |
23 Jun 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-23 17:15
Updated : 2025-06-26 12:25
NVD link : CVE-2025-6516
Mitre link : CVE-2025-6516
CVE.ORG link : CVE-2025-6516
JSON object : View
Products Affected
hdfgroup
- hdf5