PT-2022-7538 · Hdf5+4 · Hdf5+4

Published

2022-08-22

·

Updated

2024-11-08

·

CVE-2024-29158

CVSS v3.1

7.4

High

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HDF5 versions prior to 1.14.4
Description The issue is related to a stack buffer overflow in the H5FL arr malloc function, which can lead to denial of service or potential code execution. This may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For HDF5 versions prior to 1.14.4, update to version 1.14.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the H5FL arr malloc function until a patch is available.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-40555
AZL-40720
BDU:2024-07112
CVE-2024-29158
ECHO-257B-64F2-7538
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340
OPENSUSE-SU-2024_2195-1
OPENSUSE-SU-2024_3144-1
RHSA-2025:3801
SUSE-SU-2024:2105-1
SUSE-SU-2024:2195-1
SUSE-SU-2024:3144-1

Affected Products

Astra Linux
Debian
Hdf5
Red Os
Suse