cbcvebase.
CVE-2025-2914
published 2025-03-28

CVE-2025-2914: A vulnerability classified as problematic has been found in HDF5 up to 1.14.6. This affects the function H5FS__sinfo_Srialize_Sct_cb of the file…

PriorityP414low3.3CVSS 3.1
AVLACLPRLUINSUCNINAL
EPSS
0.26%
16.8th percentile
A vulnerability classified as problematic has been found in HDF5 up to 1.14.6. This affects the function H5FS__sinfo_Srialize_Sct_cb of the file src/H5FScache.c. The manipulation of the argument sect leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used.

Affected

13 ranges
VendorProductVersion rangeFixed in
debianhdf5
hdfgrouphdf5<= 1.14.6
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
hdfgrouphdf5
msrcazl3_hdf5_1.14.4.3-1_on_azure_linux_3.0
msrcazl3_hdf5_1.14.6-1_on_azure_linux_3.0
msrccbl2_hdf5_1.14.4-1_on_cbl_mariner_2.0
msrccbl2_hdf5_1.14.6-1_on_cbl_mariner_2.0

CVSS provenance

nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
nvdv4.01.9LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.01.7LOWAV:L/AC:L/Au:S/C:N/I:N/A:P
osv4.8MEDIUM
vendor_debian4.8LOW
vendor_redhat4.8MEDIUM
vendor_msrc3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.