Msrc Cbl2 Hdf5 1.12.1-13 On Cbl Mariner 2.0 vulnerabilities

30 known vulnerabilities affecting msrc/cbl2_hdf5_1.12.1-13_on_cbl_mariner_2.0.

Total CVEs
30
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH17MEDIUM5

Vulnerabilities

Page 1 of 2
CVE-2024-32611CRITICALCVSS 9.82024-05-14
CVE-2024-32611 [CRITICAL] CWE-457 HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c. HDF5 Library through 1.14.3 may use an uninitialized value in H5A__attr_release_table in H5Aint.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to da
msrc
CVE-2024-32622CRITICALCVSS 9.12024-05-14
CVE-2024-32622 [CRITICAL] CWE-125 HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c). HDF5 Library through 1.14.3 contains a out-of-bounds read operation in H5FL_arr_malloc in H5FL.c (called from H5S_set_extent_simple in H5S.c). FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our
msrc
CVE-2024-32621CRITICALCVSS 9.82024-05-14
CVE-2024-32621 [CRITICAL] CWE-122 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c) resulting in the corruption of the instruction pointer HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5HG_read in H5HG.c (called from H5VL__native_blob_get in H5VLnative_blob.c) resulting in the corruption of the instruction pointer. FAQ: Is Azure Linux the only Microsoft product that includes t
msrc
CVE-2024-29164CRITICALCVSS 9.82024-05-14
CVE-2024-29164 [CRITICAL] CWE-121 HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_heap resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and i
msrc
CVE-2024-33874CRITICALCVSS 9.82024-05-14
CVE-2024-33874 [CRITICAL] CWE-120 HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c. HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_new_encode in H5Omtime.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with
msrc
CVE-2024-29157CRITICALCVSS 9.82024-05-14
CVE-2024-29157 [CRITICAL] CWE-122 HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore pote
msrc
CVE-2024-29159CRITICALCVSS 9.82024-05-14
CVE-2024-29159 [CRITICAL] CWE-120 HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and
msrc
CVE-2024-32615CRITICALCVSS 9.82024-05-14
CVE-2024-32615 [CRITICAL] CWE-787 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c caused by the earlier use of an initialized pointer. HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5Z__nbit_decompress_one_byte in H5Znbit.c caused by the earlier use of an initialized pointer. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vul
msrc
CVE-2024-32613HIGHCVSS 7.42024-05-14
CVE-2024-32613 [HIGH] CWE-122 HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c a different vulnerability than CVE-2024-32612. HDF5 Library through 1.14.3 contains a heap-based buffer over-read in the function H5HL__fl_deserialize in H5HLcache.c a different vulnerability than CVE-2024-32612. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulne
msrc
CVE-2024-32616HIGHCVSS 7.42024-05-14
CVE-2024-32616 [HIGH] CWE-122 HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c. HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5O__dtype_encode_helper in H5Odtype.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment t
msrc
CVE-2024-32620HIGHCVSS 7.42024-05-14
CVE-2024-32620 [HIGH] CWE-122 HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c resulting in the corruption of the instruction pointer. HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c resulting in the corruption of the instruction pointer. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of
msrc
CVE-2024-32614HIGHCVSS 8.82024-05-14
CVE-2024-32614 [HIGH] CWE-125 HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c. HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source
msrc
CVE-2024-32605HIGHCVSS 8.82024-05-14
CVE-2024-32605 [HIGH] CWE-122 HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c). HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c). FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers
msrc
CVE-2024-29162HIGHCVSS 7.42024-05-14
CVE-2024-29162 [HIGH] CWE-122 HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read resulting in denial of service or potential code execution. HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read resulting in denial of service or potential code execution. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers
msrc
CVE-2024-32609HIGHCVSS 7.52024-05-14
CVE-2024-32609 [HIGH] CWE-674 HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c. HDF5 Library through 1.14.3 allows stack consumption in the function H5E_printf_stack in H5Eint.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date w
msrc
CVE-2024-29160HIGHCVSS 7.42024-05-14
CVE-2024-29160 [HIGH] CWE-122 HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_heap_deserialize resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. FAQ: Is Azure Linux the only Microsoft product that includes this open-so
msrc
CVE-2024-32617HIGHCVSS 8.82024-05-14
CVE-2024-32617 [HIGH] CWE-122 HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c). HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM_xstrdup in H5MM.c (called from H5G__ent_to_link in H5Glink.c). FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected
msrc
CVE-2024-29165HIGHCVSS 7.42024-05-14
CVE-2024-29165 [HIGH] CWE-122 HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32 resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher32 resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is th
msrc
CVE-2024-29158HIGHCVSS 7.42024-05-14
CVE-2024-29158 [HIGH] CWE-122 HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_malloc resulting in the corruption of the instruction pointer and causing denial of service or potential code execution. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is ther
msrc
CVE-2024-33877HIGHCVSS 8.82024-05-14
CVE-2024-33877 [HIGH] CWE-122 HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c. HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__conv_struct_opt in H5Tconv.c. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date w
msrc