CVE-2024-32622: Critical severity hdf5 vulnerability
Published May 14, 2024
·Updated
HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FLarrmalloc in H5FL.c (called from H5Ssetextentsimple in H5S.c).
Affected Software
2 affected components
HDFGroup hdf5<1.14.4
HDF Group HDF5 Library<=1.14.3
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·03:36 PM
Aug 20, 2024
Data Sourced
via MITRE·01:34 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-32622?
CVE-2024-32622 is classified as a medium severity vulnerability due to the potential for out-of-bounds read operations.
2
How do I fix CVE-2024-32622?
The recommended fix for CVE-2024-32622 is to upgrade to HDF5 Library version 1.14.4 or higher.
3
What components are affected by CVE-2024-32622?
CVE-2024-32622 affects the HDF5 Library version 1.14.3 and earlier.
4
What type of vulnerability is CVE-2024-32622?
CVE-2024-32622 is an out-of-bounds read vulnerability that can lead to information disclosure.
5
In which function does CVE-2024-32622 occur?
CVE-2024-32622 occurs in the H5FL_arr_malloc function within the H5FL.c file.