HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoffset, resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
The vulnerability results from improper buffer handling (CWE-120 — classic buffer overflow) in the H5Z__filter_scaleoffset data filtering function, which is part of the HDF5 data compression/transformation mechanism. Buffer overflow overwrites the instruction pointer, disrupting normal program execution flow. As a result, an attacker can cause application failure or — under favorable conditions — take control of code execution through a crafted HDF5 file.
An attacker can cause denial of service (DoS) by crashing an application processing an HDF5 file or, in case of successful exploitation, gain the ability to execute code remotely (RCE) in the context of the victim's process.
The HDF5 library should be updated to version 1.14.4 or newer, where the vendor has provided fixes for this and related vulnerabilities. Details are available in the vendor's statement at: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
HDF5 (Hdfgroup) in versions up to and including 1.14.3.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHdfgroup Hdf5
APPHdfgroup< 1.14.4
Related vulnerabilities
Podatność RCE/DoS w bibliotece HDF5 — uszkodzenie pamięci w H5A__close
HDF5 Library: użycie niezainicjowanej wartości w H5A__attr_release_table
HDF5: heap buffer overflow w H5HG_read umożliwiający RCE lub DoS
Stack buffer overflow w HDF5 — RCE lub DoS przez uszkodzenie wskaźnika instrukcji
HDF5 Library: heap-based buffer overflow w dekompresji nbit