CVE-2021-45830
published 2022-01-05CVE-2021-45830: A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
PriorityP421medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.70%
49.1th percentile
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | < hdf5 1.14.5+repack-1 (forky) | hdf5 1.14.5+repack-1 (forky) |
| hdfgroup | hdf5 | — | — |
| hdfgroup | hdf5 | >= 0 < 1.14.5+repack-1 | 1.14.5+repack-1 |
| hdfgroup | hdf5 | >= 0 < 1.14.5+repack-1 | 1.14.5+repack-1 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv5.5MEDIUM
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5h2h-fjjr-x9m2: A heap-based buffer overflow vulnerability exists in HDF5 1
ghsa_unreviewed·2022-01-06
CVE-2021-45830 [MEDIUM] CWE-787 GHSA-5h2h-fjjr-x9m2: A heap-based buffer overflow vulnerability exists in HDF5 1
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
OSV
CVE-2021-45830: A heap-based buffer overflow vulnerability exists in HDF5 1
osv·2022-01-05·CVSS 5.5
CVE-2021-45830 [MEDIUM] CVE-2021-45830: A heap-based buffer overflow vulnerability exists in HDF5 1
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
Red Hat
hdf5: heap buffer overflow vulnerability in H5F_addr_decode_len in /hdf5/src/H5Fint.c
vendor_redhat·2022-01-05·CVSS 5.5
CVE-2021-45830 [MEDIUM] CWE-787 hdf5: heap buffer overflow vulnerability in H5F_addr_decode_len in /hdf5/src/H5Fint.c
hdf5: heap buffer overflow vulnerability in H5F_addr_decode_len in /hdf5/src/H5Fint.c
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
Statement: In Red Hat OpenStack Platform 16 the hdf5 package is not actually utilized. Red Hat OpenStack Platform 13 will be retiring soon. For these reasons and because the flaw's impact is lower, no update will be provided at this time for the hdf5 package.
Package: hdf5 (Red Hat OpenStack Platform 13 (Queens)) - Out of support scope
Package: hdf5 (Red Hat OpenStack Platform 16.1) - Will not fix
Debian
CVE-2021-45830: hdf5 - A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_...
vendor_debian·2021·CVSS 5.5
CVE-2021-45830 [MEDIUM] CVE-2021-45830: hdf5 - A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_...
A heap-based buffer overflow vulnerability exists in HDF5 1.13.1-1 via H5F_addr_decode_len in /hdf5/src/H5Fint.c, which could cause a Denial of Service.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-01-05
Published