CVE-2025-2913
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Mar 28, 2025
CWE ID 121
Summary
CVE-2025-2913 is a newly discovered vulnerability affecting HDF5 versions up to 1.14.6. This issue, rated as problematic, resides in the H5FL__blk_gc_list function of the file src/HDF5.c. The vulnerability stems from a use-after-free condition triggered by manipulating the argument H5FL_blk_head_t. An attacker can exploit this locally, and the exploit for this vulnerability has been made public.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd