CVE-2024-32608
published 2024-10-09CVE-2024-32608: HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.67%
48.0th percentile
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | < hdf5 1.14.5+repack-1 (forky) | hdf5 1.14.5+repack-1 (forky) |
| hdfgroup | hdf5 | < 1.14.4 | 1.14.4 |
| hdfgroup | hdf5 | >= 0 < 1.14.5+repack-1 | 1.14.5+repack-1 |
| hdfgroup | hdf5 | >= 0 < 1.14.5+repack-1 | 1.14.5+repack-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hdf5: multiple CVEs
vendor_redhat·2024-05-10·CVSS 9.8
CVE-2024-32608 [CRITICAL] hdf5: multiple CVEs
hdf5: multiple CVEs
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
HDF5 library contains a memory corruption issue in H5A__close() function resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Package: hdf5 (Red Hat OpenStack Platform 16.1) - Out of support scope
Debian
CVE-2024-32608: hdf5 - HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the...
vendor_debian·2024·CVSS 9.8
CVE-2024-32608 [CRITICAL] CVE-2024-32608: hdf5 - HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the...
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.14.5+repack-1)
sid: resolved (fixed in 1.14.5+repack-1)
trixie: resolved (fixed in 1.14.5+repack-1)
GHSA
GHSA-7646-3v28-562q: HDF5 library through 1
ghsa_unreviewed·2024-10-09
CVE-2024-32608 [CRITICAL] CWE-787 GHSA-7646-3v28-562q: HDF5 library through 1
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
OSV
CVE-2024-32608: HDF5 library through 1
osv·2024-10-09·CVSS 9.8
CVE-2024-32608 [CRITICAL] CVE-2024-32608: HDF5 library through 1
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
No detection rules found.
No public exploits indexed.
2024-10-09
Published