Vulnerability Description
A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointer dereference. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hdfgroup | Hdf5 | <= 1.14.6 |
Related Weaknesses (CWE)
References
- https://github.com/HDFGroup/hdf5/issues/5384ExploitIssue Tracking
- https://vuldb.com/?ctiid.301901Permissions RequiredVDB Entry
- https://vuldb.com/?id.301901Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.521246Third Party AdvisoryVDB Entry
- https://github.com/HDFGroup/hdf5/issues/5384ExploitIssue Tracking
FAQ
What is CVE-2025-2926?
CVE-2025-2926 is a vulnerability with a CVSS score of 3.3 (LOW). A vulnerability was found in HDF5 up to 1.14.6 and classified as problematic. This issue affects the function H5O__cache_chk_serialize of the file src/H5Ocache.c. The manipulation leads to null pointe...
How severe is CVE-2025-2926?
CVE-2025-2926 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-2926?
Check the references section above for vendor advisories and patch information. Affected products include: Hdfgroup Hdf5.