CVE-2025-2912
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 28, 2025
CWE ID 121
Summary
CVE-2025-2912 is a recently identified vulnerability in HDF5 versions up to 1.14.6. This issue impacts the function H5O_msg_flush located in src/H5Omessage.c. An attacker can exploit this heap-based buffer overflow by manipulating the argument 'oh'. To successfully exploit this vulnerability, an attacker must have local access. The exploit for this vulnerability has been disclosed to the public, increasing the risk of potential exploitation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd