Impact
A heap-based buffer over-read occurs in the scale-offset filter routine of the HDF5 library when decoding a compressed chunk. The vulnerability triggers an application crash if the stored minimum bits equal the datatype precision, causing the decoder to copy too many bytes from the chunk without bounds checking. This results in a denial of service by exhausting memory or corrupting critical data structures.
Affected Systems
The weakness affects the HDF Group's HDF5 implementation up to and including version 2.2.0. Any system or application that loads HDF5 files containing the scale‑offset filter can be impacted, regardless of the operating system or hardware platform.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by presenting a maliciously crafted HDF5 file to any application that processes it, so the likely attack vector is local file usage or remote delivery if the file is transmitted over network and then decoded. The lack of mandatory boundary checks means the exploit requires only read access to the target file.
OpenCVE Enrichment