PT-2022-7546 · Hdf5+2 · Hdf5+2

Published

2022-08-22

·

Updated

2026-01-29

·

CVE-2024-29164

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HDF5 versions 1.14.3 and earlier
Description The issue is related to a stack buffer overflow in the H5R decode heap() function of the HDF5 library. This overflow can cause corruption of the instruction pointer, leading to denial of service or potential code execution. The vulnerability can be exploited by a remote attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For HDF5 versions 1.14.3 and earlier, as a temporary workaround, consider disabling the H5R decode heap() function until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Stack Overflow

Weakness Enumeration

Related Identifiers

AZL-40603
AZL-40744
BDU:2024-07146
CVE-2024-29164
ECHO-646E-DBCD-16FB
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340
RHSA-2025:3801

Affected Products

Debian
Hdf5
Red Os