Impact
In HDF5 versions before 2.3.0 the function H5Z__filter_nbit in H5Znbit.c dereferences the client‑data array cd_values[0] through cd_values[4] without validating that cd_values is non‑NULL or that cd_nelmts is at least five, the fixed size of the filter header. An attacker can exploit this by crafting an HDF5 file that contains an N‑Bit filter pipeline message whose header has zero client‑data values and then opening that file with H5Dread, for example via the tools h5ls or h5repack. The program will dereference a null or short array, causing an out‑of‑bounds read and a crash. The weakness is a null pointer dereference and an array bounds violation (CWE‑1284, CWE‑476). The impact is limited to a denial of service through a process crash; no information disclosure or code execution is possible.
Affected Systems
The HDF Group’s HDF5 library, versions through 2.3.0, is affected. Any installation that uses HDF5 to read or process external HDF5 files, including the command‑line tools h5ls and h5repack, is potentially vulnerable.
Risk and Exploitability
The CVSS score of 6.8 indicates medium severity. The EPSS score is <1%, so the current exploitation probability is very low but not zero. The vulnerability is not listed in CISA KEV. Attackers would need to supply a malicious HDF5 file that the target system reads; common vectors include data ingestion workflows or local users tricking the system into opening a crafted file. Because the flaw is triggered by a file‑reading routine, exploitation requires that the application accept untrusted files; a successful exploit will simply crash the HDF5 process, resulting in denial of service.
OpenCVE Enrichment