CVE-2025-2923: HDF5 H5Fint.c H5F_addr_encode_len heap-based overflow
A vulnerability, which was classified as problematic, has been found in HDF5 up to 1.14.6. Affected by this issue is the function H5Faddrencodelen of the file src/H5Fint.c. The manipulation of the argument pp leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Other sources
HDF5 H5Fint.c H5Faddrencodelen heap-based overflow
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2923?
CVE-2025-2923 is classified as a problematic severity vulnerability.
How do I fix CVE-2025-2923?
To fix CVE-2025-2923, upgrade HDF5 to version 1.14.7 or later.
What is the impact of CVE-2025-2923?
CVE-2025-2923 can lead to a heap-based buffer overflow when manipulating arguments in the H5F_addr_encode_len function.
Who is affected by CVE-2025-2923?
Users of HDF5 versions up to 1.14.6 are affected by CVE-2025-2923.
Is local access required to exploit CVE-2025-2923?
Yes, local access is required to exploit the vulnerability described in CVE-2025-2923.