Impact
The vulnerability is a heap use‑after‑free in the h5dump helper utility of HDF5. A malicious .h5 file can trigger a call to memmove that accesses memory that has already been freed, producing memory corruption that can corrupt data structures or crash the process.
Affected Systems
HDFGroup’s HDF5 library, versions 1.14.1, 1.14.2, and earlier, is affected when the h5dump utility is used. Any installation that processes external HDF5 files with these releases is vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of less than 1 % shows a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a crafted .h5 file to the target system’s h5dump utility or application that uses it; processing the file can lead to instability or data corruption.
OpenCVE Enrichment