CVE-2025-2924: HDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflow
A vulnerability, which was classified as problematic, was found in HDF5 up to 1.14.6. This affects the function H5HLfldeserialize of the file src/H5HLcache.c. The manipulation of the argument freeblock leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Other sources
HDF5 H5HLcache.c H5HLfldeserialize heap-based overflow
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2924?
CVE-2025-2924 is classified as problematic due to the potential for a heap-based buffer overflow.
How do I fix CVE-2025-2924?
To fix CVE-2025-2924, upgrade to HDF5 version 1.14.7 or later.
What versions of HDF5 are affected by CVE-2025-2924?
CVE-2025-2924 affects HDF5 versions up to and including 1.14.6.
What kind of attack can be launched using CVE-2025-2924?
CVE-2025-2924 allows for a heap-based buffer overflow attack which can lead to arbitrary code execution.
Who is responsible for the HDF5 vulnerability identified as CVE-2025-2924?
The HDF Group is responsible for maintaining HDF5 and addressing vulnerabilities like CVE-2025-2924.