CVE-2025-2924

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 28, 2025
Updated: Apr 17, 2025
CWE ID 119
CWE ID 122
CWE ID 787

Summary

CVE-2025-2924 is a newly disclosed vulnerability in HDF5 versions up to 1.14.6. The issue lies within the function H5HL__fl_deserialize in src/H5HLcache.c, where a heap-based buffer overflow can occur due to the manipulation of the argument free_block. This local exploit has been made public, increasing the risk of potential attacks. The vulnerability was classified as problematic, and successful exploitation could result in significant consequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share