cbcvebase.
CVE-2025-2913
published 2025-03-28

CVE-2025-2913: A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5FL__blk_gc_list of the file src/H5FL.c…

PriorityP429medium5.3CVSS 3.1
AVLACLPRLUINSUCLILAL
EPSS
0.23%
13.8th percentile
A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5FL__blk_gc_list of the file src/H5FL.c. The manipulation of the argument H5FL_blk_head_t leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianhdf5
hdfgrouphdf5< 2.0.02.0.0
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
msrcazl3_hdf5_1.14.4.3-1_on_azure_linux_3.0
msrccbl2_hdf5_1.14.4-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
vendor_msrc3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.