CVE-2025-2913

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 121

Summary

CVE-2025-2913 is a newly discovered vulnerability affecting HDF5 versions up to 1.14.6. This issue, rated as problematic, resides in the H5FL__blk_gc_list function of the file src/HDF5.c. The vulnerability stems from a use-after-free condition triggered by manipulating the argument H5FL_blk_head_t. An attacker can exploit this locally, and the exploit for this vulnerability has been made public.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share