CVE-2025-2926: HDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference
A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5Ocachechkserialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Other sources
HDF5 H5Ocache.c H5Ocachechkserialize null pointer dereference
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2926?
CVE-2025-2926 is classified as problematic due to the potential for a null pointer dereference.
How do I fix CVE-2025-2926?
To mitigate CVE-2025-2926, upgrade HDF5 to version 1.14.7 or later.
What software is affected by CVE-2025-2926?
CVE-2025-2926 affects HDF5 up to version 1.14.6.
Can CVE-2025-2926 be exploited remotely?
CVE-2025-2926 requires local access to exploit, as it cannot be exploited remotely.
What is the nature of the vulnerability in CVE-2025-2926?
The vulnerability in CVE-2025-2926 is a null pointer dereference that occurs in the H5O__cache_chk_serialize function.