Impact
A heap-based buffer overflow occurs in GDapi.c's GDSDfldsrch function when processing Grid File data. This flaw can allow an attacker with local execution rights to corrupt memory and potentially hijack execution flow, leading to arbitrary code execution or denial of service. The weakness corresponds to CWE-119, CWE-122, and CWE-125.
Affected Systems
The vulnerability affects OSGeo GDAL versions up to and including 3.13.0dev-4. The affected component is the Grid File Handler used when reading certain HDF4/HDF-EOS files. The vendor has released a patch in version 3.13.0RC1, identified by commit 3e04c0385630e4d42517046d9a4967dfccfeb7fd. Systems running any earlier GDAL release are susceptible.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. The exploit is local only, limiting risk to machines where an attacker can run code. The EPSS score of 0.00014 (less than 1%) shows a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The public disclosure means the flaw is known to attackers, and with sufficient local access the overflow is straightforward to trigger.
OpenCVE Enrichment