CVE-2025-2925
EUVD-2025-865328.03.2025, 20:15
A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hdfgroup | hdf5 | 𝑥 ≤ 1.14.6 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration
- CWE-119 - Improper Restriction of Operations within the Bounds of a Memory BufferThe software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.
- CWE-415 - Double FreeThe product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.