CVE-2024-32610: Use After Free
Published May 14, 2024
·Updated
HDF5 Library through 1.14.3 has a SEGV in H5Tclosereal in H5T.c, resulting in a corrupted instruction pointer.
Affected Software
2 affected components
HDFGroup hdf5<1.14.4
The HDF Group HDF5 Library<=1.14.3
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:36 PM
Dec 3, 2024
Data Sourced
via MITRE·04:01 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-32610?
CVE-2024-32610 has a high severity due to its potential to cause a segmentation fault and result in application crashes.
2
How do I fix CVE-2024-32610?
To fix CVE-2024-32610, upgrade the HDF5 Library to version 1.14.4 or later.
3
What systems are affected by CVE-2024-32610?
CVE-2024-32610 affects all versions of the HDF5 Library up to and including 1.14.3.
4
What are the implications of CVE-2024-32610 on software using HDF5?
The implications of CVE-2024-32610 include potential application instability and data corruption when using affected HDF5 Library versions.
5
Is there a workaround for CVE-2024-32610 if I cannot update immediately?
Currently, there are no known workarounds for CVE-2024-32610, and upgrading to the latest version is strongly recommended.