PT-2022-7539 · Hdf5+2 · Hdf5+2

Published

2022-08-22

·

Updated

2026-01-29

·

CVE-2024-29157

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HDF5 versions 1.14.3 and earlier
Description The issue is related to a heap buffer overflow in the H5HG read() function of the HDF5 library. This overflow can lead to the corruption of the instruction pointer, resulting in denial of service or potential code execution. The exploitation of this issue may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For HDF5 versions 1.14.3 and earlier, as a temporary workaround, consider disabling the H5HG read() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-40622
AZL-40726
BDU:2024-07113
CVE-2024-29157
ECHO-FC9E-24DE-4F3B
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340
RHSA-2025:3801

Affected Products

Debian
Hdf5
Red Os