VulnerabilityAnalyzed
CVE-2025-2309
A vulnerability has been found in HDF5 1.14.6 and classified as critical.
MEDIUM 4.8EPSS 0.36%
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__bit_copy of the component Type Conversion Logic. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.
- CVSS 4.0
- 4.8 MEDIUMCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-122, CWE-787
- Affected
- hdfgroup/hdf5
- Source
- cna@vuldb.com
References
- https://github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc3.mdExploit, Third Party Advisory
- https://vuldb.com/?ctiid.299722Permissions Required, VDB Entry
- https://vuldb.com/?id.299722Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.514532Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.