CVE-2025-6269: HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow
A vulnerability classified as critical was found in HDF5 up to 1.14.6. Affected by this vulnerability is the function H5Creconstructcacheentry of the file H5Cimage.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
Other sources
HDF5 H5Cimage.c H5Creconstructcacheentry heap-based overflow
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6269?
CVE-2025-6269 is classified as a critical vulnerability.
How do I fix CVE-2025-6269?
The recommended fix for CVE-2025-6269 is to update HDF5 to a version greater than 1.14.6.
What effects can CVE-2025-6269 have on my system?
CVE-2025-6269 can lead to a heap-based buffer overflow, which may allow for escalated privileges or execution of arbitrary code.
Is local access required to exploit CVE-2025-6269?
Yes, exploiting CVE-2025-6269 requires local access to the affected system.
Which versions of HDF5 are affected by CVE-2025-6269?
CVE-2025-6269 affects HDF5 versions up to and including 1.14.6.