Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-2926

Опубликовано: 28 мар. 2025
Источник: debian
EPSS Низкий

Описание

A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
hdf5fixed2.1.0+repack-1package

Примечания

  • https://github.com/HDFGroup/hdf5/issues/5384

  • https://github.com/HDFGroup/hdf5/pull/5841

  • https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2 (2.0.0)

  • HDF not covered by security support, see https://bugs.debian.org/1117722

EPSS

Процентиль: 15%
0.00239
Низкий

Связанные уязвимости

CVSS3: 3.3
ubuntu
больше 1 года назад

A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
redhat
больше 1 года назад

A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
nvd
больше 1 года назад

A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

CVSS3: 3.3
msrc
12 месяцев назад

HDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference

CVSS3: 3.3
github
больше 1 года назад

A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

EPSS

Процентиль: 15%
0.00239
Низкий