CVE-2025-6857: HDF5 H5Gnode.c H5G__node_cmp3 stack-based overflow
A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5Gnodecmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Other sources
HDF5 H5Gnode.c H5Gnodecmp3 stack-based overflow
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6857?
CVE-2025-6857 is classified as a problematic vulnerability due to the stack-based buffer overflow it can cause.
How do I fix CVE-2025-6857?
To fix CVE-2025-6857, update to the latest version of HDF5 that addresses this vulnerability.
What file is affected by CVE-2025-6857?
CVE-2025-6857 specifically affects the function H5G__node_cmp3 in the file src/H5Gnode.c.
Can CVE-2025-6857 be exploited remotely?
CVE-2025-6857 is a local vulnerability, meaning it can only be exploited on the local host.
Which software versions are impacted by CVE-2025-6857?
CVE-2025-6857 impacts HDF5 version 1.14.6.