A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
History

Thu, 17 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Hdfgroup
Hdfgroup hdf5
CPEs cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:*
Vendors & Products Hdfgroup
Hdfgroup hdf5

Wed, 02 Apr 2025 02:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Fri, 28 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
Title HDF5 H5Ocache.c H5O__cache_chk_serialize null pointer dereference
Weaknesses CWE-404
CWE-476
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-03-28T20:22:50.493Z

Reserved: 2025-03-28T11:56:29.079Z

Link: CVE-2025-2926

cve-icon Vulnrichment

Updated: 2025-03-28T20:22:46.517Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-28T20:15:26.980

Modified: 2025-04-17T14:31:21.250

Link: CVE-2025-2926

cve-icon Redhat

Severity : Low

Publid Date: 2025-03-28T20:00:13Z

Links: CVE-2025-2926 - Bugzilla