CVE-2025-44904
published 2025-05-30CVE-2025-44904: hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
PriorityP344high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.38%
30.1th percentile
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | hdf5 | — | — |
| hdfgroup | hdf5 | — | — |
| msrc | azl3_hdf5_1.14.6-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_hdf5_1.14.6-2_on_azure_linux_3.0 | — | — |
| msrc | cbl2_hdf5_1.14.6-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_hdf5_1.14.6-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.8LOW
vendor_msrc8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-77wp-p4v3-xgj7: hdf5 v1
ghsa_unreviewed·2025-05-30
CVE-2025-44904 [HIGH] CWE-122 GHSA-77wp-p4v3-xgj7: hdf5 v1
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
OSV
CVE-2025-44904: hdf5 v1
osv·2025-05-30·CVSS 8.8
CVE-2025-44904 [HIGH] CVE-2025-44904: hdf5 v1
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
Red Hat
hdf5: Heap Buffer Overflow in HDF5 H5VM_memcpyvv Function
vendor_redhat·2025-05-30·CVSS 8.8
CVE-2025-44904 [HIGH] CWE-122 hdf5: Heap Buffer Overflow in HDF5 H5VM_memcpyvv Function
hdf5: Heap Buffer Overflow in HDF5 H5VM_memcpyvv Function
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
A flaw was found in the H5VM_memcpyvv function in the HDF5 library. This vulnerability can allow memory corruption and application crashes via reading from a specially crafted compact dataset, leading to a heap-based buffer overflow.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: hdf5 (Red Hat Enterprise Linux AI (RHEL AI)) - Fix deferred
Microsoft
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
vendor_msrc·2025-05-13·CVSS 8.8
CVE-2025-44904 [HIGH] CWE-122 hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
Mariner: Mariner
mitre: mitre
Customer Action Required: Yes
Debian
CVE-2025-44904: hdf5 - hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcp...
vendor_debian·2025·CVSS 8.8
CVE-2025-44904 [HIGH] CVE-2025-44904: hdf5 - hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcp...
hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
2025-05-30
Published