PT-2024-6202 · Hdf5+2 · Hdf5+2

Published

2024-05-09

·

Updated

2026-03-29

·

CVE-2024-32615

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions HDF5 versions prior to 1.14.3
Description The issue is related to a heap-based buffer overflow in the H5Z nbit decompress one byte() function in the H5Znbit.c file of the HDF5 library. This overflow is caused by the earlier use of an initialized pointer. Exploitation of this issue may allow an attacker to impact the confidentiality, integrity, and availability of protected information.
Recommendations For versions prior to 1.14.3, update to a version that contains a fix for this issue. As a temporary workaround, consider restricting access to the H5Z nbit decompress one byte() function in the H5Znbit.c file until a patch is available.

Exploit

Fix

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-40540
AZL-40738
BDU:2024-07133
CVE-2024-32615
ECHO-27AA-AE20-6FB4
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340
RHSA-2025:3801

Affected Products

Debian
Hdf5
Red Os