CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-29159

CVSS 9.8v3.1pub. 2024-05-14upd. 2025-04-18

HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.

🤖 AI Analysis
How it works

The vulnerability results from improper buffer handling (CWE-120 — classic buffer overflow) in the H5Z__filter_scaleoffset data filtering function, which is part of the HDF5 data compression/transformation mechanism. Buffer overflow overwrites the instruction pointer, disrupting normal program execution flow. As a result, an attacker can cause application failure or — under favorable conditions — take control of code execution through a crafted HDF5 file.

Impact

An attacker can cause denial of service (DoS) by crashing an application processing an HDF5 file or, in case of successful exploitation, gain the ability to execute code remotely (RCE) in the context of the victim's process.

Mitigation & patch

The HDF5 library should be updated to version 1.14.4 or newer, where the vendor has provided fixes for this and related vulnerabilities. Details are available in the vendor's statement at: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/

Who is affected

HDF5 (Hdfgroup) in versions up to and including 1.14.3.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Hdfgroup Hdf5

    APP
    Hdfgroup
    < 1.14.4
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEDoSMemory
CWE
References

Related vulnerabilities

CVE-2024-32608CRITICAL9.8PL ✓same product

Podatność RCE/DoS w bibliotece HDF5 — uszkodzenie pamięci w H5A__close

CVE-2024-32611CRITICAL9.8PL ✓same product

HDF5 Library: użycie niezainicjowanej wartości w H5A__attr_release_table

CVE-2024-29157CRITICAL9.8PL ✓same product

HDF5: heap buffer overflow w H5HG_read umożliwiający RCE lub DoS

CVE-2024-29164CRITICAL9.8PL ✓same product

Stack buffer overflow w HDF5 — RCE lub DoS przez uszkodzenie wskaźnika instrukcji

CVE-2024-32615CRITICAL9.8PL ✓same product

HDF5 Library: heap-based buffer overflow w dekompresji nbit