Impact
A heap-use-after-free flaw exists in the H5T__conv_f_f function of HDF5, triggered when converting compound datatypes that contain floating-point members during a dataset read. The routine frees a temporary buffer allocated with calloc() and later reads from it, leading to a crash and, depending on heap layout and allocator behavior, potential memory corruption and remote code execution.
Affected Systems
The flaw affects The HDF Group's HDF5 library versions earlier than 1.14.2. Any application that reads such datasets in a vulnerable file, such as the h5dump utility, is susceptible.
Risk and Exploitability
The CVSS score of 4.6 positions the vulnerability at a moderate level. The EPSS score of less than 1% suggests current exploitation activity is low, and the feature is not listed in CISA's KEV catalog. However, the attack vector is straightforward: an attacker crafts an HDF5 file with a specially constructed compound datatype, and a victim application opens the file to read the dataset. The lack of required authentication and the reliance on parsing user-supplied data make the exploitation path simple, though achieving full remote code execution would also depend on the underlying heap state and allocator behavior.
OpenCVE Enrichment