CVE-2025-6858: HDF5 H5Centry.c H5C__flush_single_entry null pointer dereference
A vulnerability was found in HDF5 1.14.6 and classified as problematic. Affected by this issue is the function H5Cflushsingleentry of the file src/H5Centry.c. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Other sources
HDF5 H5Centry.c H5Cflushsingleentry null pointer dereference
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6858?
CVE-2025-6858 is classified as a problematic vulnerability due to the potential for null pointer dereference.
How do I fix CVE-2025-6858?
To mitigate CVE-2025-6858, users should upgrade to a fixed version of HDF5 provided by HDF Group.
What causes the vulnerability CVE-2025-6858?
CVE-2025-6858 is caused by a null pointer dereference in the function H5C__flush_single_entry within HDF5.
Is CVE-2025-6858 exploitable remotely?
CVE-2025-6858 requires local access to exploit the vulnerability effectively.
What products are affected by CVE-2025-6858?
CVE-2025-6858 affects HDF5 version 1.14.6 from HDF Group.