CVE-2025-6516: HDF5 H5Fint.c H5F_addr_decode_len heap-based overflow
Published Jun 23, 2025
·Updated
A vulnerability has been found in HDF5 up to 1.14.6 and classified as critical. This vulnerability affects the function H5Faddrdecodelen of the file /hdf5/src/H5Fint.c. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
HDF Group HDF5<=1.14.6
HDFGroup hdf5<=1.14.6
Event History
Jun 23, 2025
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Jul 1, 57463
Event
via FIRST·04:42 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-6516?
CVE-2025-6516 is classified as a critical vulnerability.
2
How do I fix CVE-2025-6516?
To fix CVE-2025-6516, upgrade HDF5 to version 1.14.7 or later.
3
What type of vulnerability is CVE-2025-6516?
CVE-2025-6516 is a heap-based buffer overflow vulnerability.
4
What function is affected by CVE-2025-6516?
CVE-2025-6516 affects the function H5F_addr_decode_len in the file H5Fint.c.
5
Is CVE-2025-6516 exploitable remotely?
No, CVE-2025-6516 must be exploited locally.