Msrc Cbl2 Hdf5 1.14.6-1 On Cbl Mariner 2.0 vulnerabilities

21 known vulnerabilities affecting msrc/cbl2_hdf5_1.14.6-1_on_cbl_mariner_2.0.

Total CVEs
21
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH3MEDIUM6LOW12

Vulnerabilities

Page 1 of 2
CVE-2025-7067LOWCVSS 3.32025-07-08
CVE-2025-7067 [MEDIUM] CWE-122 HDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflow HDF5 H5FScache.c H5FS__sinfo_serialize_node_cb heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source
msrc
CVE-2025-7068LOWCVSS 3.32025-07-08
CVE-2025-7068 [MEDIUM] CWE-401 HDF5 H5FL.c H5FL__malloc memory leak HDF5 H5FL.c H5FL__malloc memory leak FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is c
msrc
CVE-2025-6270MEDIUMCVSS 5.32025-06-10
CVE-2025-6270 [MEDIUM] CWE-122 HDF5 H5FSsection.c H5FS__sect_find_node heap-based overflow HDF5 H5FSsection.c H5FS__sect_find_node heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries wit
msrc
CVE-2025-6269MEDIUMCVSS 5.32025-06-10
CVE-2025-6269 [MEDIUM] CWE-122 HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow HDF5 H5Cimage.c H5C__reconstruct_cache_entry heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source lib
msrc
CVE-2025-6857LOWCVSS 3.32025-06-10
CVE-2025-6857 [MEDIUM] CWE-121 HDF5 H5Gnode.c H5G__node_cmp3 stack-based overflow HDF5 H5Gnode.c H5G__node_cmp3 stack-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro
msrc
CVE-2025-6818LOWCVSS 3.32025-06-10
CVE-2025-6818 [MEDIUM] CWE-122 HDF5 H5Ochunk.c H5O__chunk_protect heap-based overflow HDF5 H5Ochunk.c H5O__chunk_protect heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which th
msrc
CVE-2025-6816LOWCVSS 3.32025-06-10
CVE-2025-6816 [MEDIUM] CWE-122 HDF5 H5Ofsinfo.c H5O__fsinfo_encode heap-based overflow HDF5 H5Ofsinfo.c H5O__fsinfo_encode heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which
msrc
CVE-2025-6858LOWCVSS 3.32025-06-10
CVE-2025-6858 [MEDIUM] CWE-476 HDF5 H5Centry.c H5C__flush_single_entry null pointer dereference HDF5 H5Centry.c H5C__flush_single_entry null pointer dereference FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source lib
msrc
CVE-2025-6750LOWCVSS 3.32025-06-10
CVE-2025-6750 [MEDIUM] CWE-122 HDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflow HDF5 H5Omtime.c H5O__mtime_new_encode heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with wh
msrc
CVE-2025-44905HIGHCVSS 7.32025-05-13
CVE-2025-44905 [HIGH] CWE-122 hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function. hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5Z__filter_scaleoffset function. FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up
msrc
CVE-2025-44904HIGHCVSS 8.82025-05-13
CVE-2025-44904 [HIGH] CWE-122 hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function. hdf5 v1.14.6 was discovered to contain a heap buffer overflow via the H5VM_memcpyvv function. Mariner: Mariner mitre: mitre Customer Action Required: Yes
msrc
CVE-2025-2915HIGHCVSS 7.52025-03-11
CVE-2025-2915 [MEDIUM] CWE-122 HDF5 H5Faccum.c H5F__accum_free heap-based overflow HDF5 H5Faccum.c H5F__accum_free heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dist
msrc
CVE-2025-2310MEDIUMCVSS 5.32025-03-11
CVE-2025-2310 [MEDIUM] CWE-122 HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source lib
msrc
CVE-2025-2308MEDIUMCVSS 5.32025-03-11
CVE-2025-2308 [MEDIUM] CWE-122 HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow HDF5 Scale-Offset Filter H5Z__scaleoffset_decompress_one_byte heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secu
msrc
CVE-2025-2153MEDIUMCVSS 6.82025-03-11
CVE-2025-2153 [LOW] CWE-122 HDF5 h5 File H5SM.c H5SM_delete heap-based overflow HDF5 h5 File H5SM.c H5SM_delete heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro
msrc
CVE-2025-2309MEDIUMCVSS 5.32025-03-11
CVE-2025-2309 [MEDIUM] CWE-122 HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow HDF5 Type Conversion Logic H5T__bit_copy heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries w
msrc
CVE-2025-2924LOWCVSS 3.32025-03-11
CVE-2025-2924 [MEDIUM] CWE-122 HDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflow HDF5 H5HLcache.c H5HL__fl_deserialize heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with wh
msrc
CVE-2025-2914LOWCVSS 3.32025-03-11
CVE-2025-2914 [MEDIUM] CWE-122 HDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflow HDF5 H5FScache.c H5FS__sinfo_Srialize_Sct_cb heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source lib
msrc
CVE-2025-2912LOWCVSS 3.32025-03-11
CVE-2025-2912 [MEDIUM] CWE-122 HDF5 H5Omessage.c H5O_msg_flush heap-based overflow HDF5 H5Omessage.c H5O_msg_flush heap-based overflow FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the dist
msrc
CVE-2025-2926LOWCVSS 3.32025-03-11
CVE-2025-2926 [MEDIUM] CWE-476 HDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference HDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability? One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source l
msrc