CVE-2025-7069: HDF5 H5FSsection.c H5FS__sect_link_size heap-based overflow
Published Jul 4, 2025
·Updated
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FSsectlinksize of the file src/H5FSsection.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
The HDF Group HDF5
HDFGroup hdf5=1.14.6
Event History
Jul 4, 2025
CVE Published
via MITRE·09:02 PM
Data Sourced
via MITRE·09:02 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Apr 29, 57559
Event
via FIRST·01:30 PM
Jun 12, 58473
Event
via NVD·09:55 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-7069?
CVE-2025-7069 is classified as a problematic vulnerability due to its potential for a heap-based buffer overflow.
2
How do I fix CVE-2025-7069?
To fix CVE-2025-7069, update to the latest version of HDF5 that addresses this vulnerability.
3
Can CVE-2025-7069 be exploited remotely?
No, CVE-2025-7069 can only be exploited locally on the host.
4
What component of HDF5 does CVE-2025-7069 affect?
CVE-2025-7069 affects the H5FS__sect_link_size function in the src/H5FSsection.c file.
5
What type of vulnerability is CVE-2025-7069?
CVE-2025-7069 is a heap-based buffer overflow vulnerability.