CVE-2025-2309

CVSS 3.0 Score 7.7 of 10 (high)

Details

Published Mar 14, 2025
CWE ID 284

Summary

CVE-2025-2309 is a critical vulnerability affecting the HDF5 1.14.6 component, specifically the Type Conversion Logic's H5T__bit_copy function. This issue results in a heap-based buffer overflow, which can be exploited through local access. The existence of this vulnerability and its exploit have been disclosed to the public, but its authenticity is currently under debate. The vendor was contacted about this issue and several others, but their response was dismissive without providing any further explanation. We are assuming the vendor intends to dispute the vulnerability until more information becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Node.js

Affected Vendors

  • OpenJS Foundation