Hdf5 · Hdf5 · CVE-2025-6270
**Name of the Vulnerable Software and Affected Versions**
HDF5 versions up to 1.14.6
**Description**
A critical issue has been found, affecting the `H5FS sect find node` function of the file H5FSsection.c, leading to a heap-based buffer overflow. The attack can be launched on the local host.
**Recommendations**
For HDF5 versions up to 1.14.6, as a temporary workaround, consider disabling the `H5FS sect find node` function until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.