CVE-2025-44904: Buffer Overflow
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VMmemcpyvv function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.14.6-3
Event History
Frequently Asked Questions
What is the severity of CVE-2025-44904?
CVE-2025-44904 has been classified as a high severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2025-44904?
To fix CVE-2025-44904, it is recommended to upgrade to HDF5 version 1.14.7 or later where the vulnerability has been patched.
What impact does CVE-2025-44904 have on HDF5?
CVE-2025-44904 enables a heap buffer overflow, which could allow an attacker to execute arbitrary code on the affected system.
Which versions of HDF5 are affected by CVE-2025-44904?
CVE-2025-44904 affects HDF5 version 1.14.6 and earlier versions.
How can I determine if my system is vulnerable to CVE-2025-44904?
You can determine if your system is vulnerable to CVE-2025-44904 by checking the version of HDF5 installed on your system.