CVE-2025-2912: HDF5 H5Omessage.c H5O_msg_flush heap-based overflow
Published Mar 28, 2025
·Updated
A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5Omsgflush of the file src/H5Omessage.c. The manipulation of the argument oh leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
HDF Group HDF5<=1.14.6
HDFGroup hdf5<2.0.0
Event History
Mar 28, 2025
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-2912?
CVE-2025-2912 is classified as a problematic vulnerability due to its potential for a heap-based buffer overflow.
2
How do I fix CVE-2025-2912?
To mitigate CVE-2025-2912, update HDF5 to version 1.14.7 or later.
3
What software is affected by CVE-2025-2912?
CVE-2025-2912 affects HDF5 versions up to and including 1.14.6.
4
What type of vulnerability is CVE-2025-2912?
CVE-2025-2912 is a heap-based buffer overflow vulnerability.
5
What function is impacted by CVE-2025-2912?
The function affected by CVE-2025-2912 is H5O_msg_flush in the HDF5 library.