PT-2024-6207 · Unknown+4 · Hdf5 Library+4

Published

2024-05-09

·

Updated

2026-03-29

·

CVE-2024-32610

CVSS v3.1

5.7

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions HDF5 Library versions 1.14.3 and earlier
Description The issue is related to a corrupted instruction pointer due to a SEGV in the H5T close real() function in the H5T.c file. This is caused by a buffer overflow in memory, which can lead to a denial of service.
Recommendations For HDF5 Library versions 1.14.3 and earlier, consider disabling the H5T close real() function as a temporary workaround until a patch is available. Restrict access to the H5T.c file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Use After Free

Buffer Overflow

Weakness Enumeration

Related Identifiers

AZL-40562
AZL-40670
BDU:2024-07138
CVE-2024-32610
ECHO-8794-D372-C600
OESA-2024-2337
OESA-2024-2338
OESA-2024-2339
OESA-2024-2340
OPENSUSE-SU-2024_2195-1
OPENSUSE-SU-2024_3144-1
SUSE-SU-2024:2105-1
SUSE-SU-2024:2195-1
SUSE-SU-2024:3144-1

Affected Products

Astra Linux
Debian
Hdf5 Library
Red Os
Suse