CVE-2025-2912

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 121

Summary

CVE-2025-2912 is a recently identified vulnerability in HDF5 versions up to 1.14.6. This issue impacts the function H5O_msg_flush located in src/H5Omessage.c. An attacker can exploit this heap-based buffer overflow by manipulating the argument 'oh'. To successfully exploit this vulnerability, an attacker must have local access. The exploit for this vulnerability has been disclosed to the public, increasing the risk of potential exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share