Vulnerability Description
A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hdfgroup | Hdf5 | 1.14.6 |
Related Weaknesses (CWE)
References
- https://github.com/HDFGroup/hdf5/issues/5571ExploitIssue Tracking
- https://github.com/user-attachments/files/20623354/hdf5_crash_3.txtExploit
- https://vuldb.com/?ctiid.314254Permissions RequiredVDB Entry
- https://vuldb.com/?id.314254Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.602291Third Party AdvisoryVDB Entry
- https://github.com/HDFGroup/hdf5/issues/5571ExploitIssue Tracking
FAQ
What is CVE-2025-6816?
CVE-2025-6816 is a vulnerability with a CVSS score of 3.3 (LOW). A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based buffer...
How severe is CVE-2025-6816?
CVE-2025-6816 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-6816?
Check the references section above for vendor advisories and patch information. Affected products include: Hdfgroup Hdf5.