CVE-2019-16091: High severity Symonics libmysofa vulnerability
Last updated 25 August 2025
Other sources
Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2019-16091?
CVE-2019-16091 is a vulnerability in Symonics libmysofa 0.7 that leads to an out-of-bounds read in directblockRead in hdf/fractalhead.c.
How severe is CVE-2019-16091?
CVE-2019-16091 has a severity rating of 7.5, which is considered high.
Which software versions are affected by CVE-2019-16091?
CVE-2019-16091 affects Symonics libmysofa 0.7 and versions 0.6~dfsg0-3+ to 0.6~dfsg0-3+deb10u1, 1.2~dfsg0-1, and 1.3.1~dfsg0-1.
How can I fix CVE-2019-16091?
To fix CVE-2019-16091, upgrade to libmysofa version 0.6~dfsg0-3+ or later if using Ubuntu, and version 0.6~dfsg0-3+deb10u1, 1.2~dfsg0-1, or 1.3.1~dfsg0-1 if using Debian.
Where can I find more information about CVE-2019-16091?
More information about CVE-2019-16091 can be found at the following references: [GitHub](https://github.com/hoene/libmysofa/compare/f571522...e07edb3), [Ubuntu Security Notices](https://usn.ubuntu.com/4473-1/), [CVE Mitre](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16091).