CVE-2025-2309: HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow
A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5Tbitcopy of the component Type Conversion Logic. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2309?
CVE-2025-2309 has been classified as a critical vulnerability due to its potential for exploitation via heap-based buffer overflow.
How do I fix CVE-2025-2309?
To mitigate CVE-2025-2309, update HDF5 to version 1.14.7 or later, which addresses the vulnerability.
Who is affected by CVE-2025-2309?
CVE-2025-2309 affects users of HDF5 version 1.14.6.
What components are impacted by CVE-2025-2309?
CVE-2025-2309 impacts the Type Conversion Logic within the H5T__bit_copy function.
Is local access required to exploit CVE-2025-2309?
Yes, exploiting CVE-2025-2309 requires local access to the system running the vulnerable version of HDF5.