Heap-Based Buffer Overflow Vulnerability in HDF5 by The HDF Group
CVE-2025-2153
2.3LOW
Key Information:
- Vendor
The HDF Group
- Status
- Vendor
- CVE Published:
- 10 March 2025
Badges
๐พ Exploit Exists
What is CVE-2025-2153?
A heap-based buffer overflow vulnerability exists in HDF5 version 1.14.6, specifically in the H5SM_delete function of the h5 File Handler. This flaw enables attackers to exploit the vulnerability remotely, leading to potential data corruption and unauthorized access. The complexity of executing this exploit is notably high, requiring advanced knowledge. The exploit has been made public, increasing the risk for systems utilizing this software version.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
HDF5 1.14.6
References
CVSS V4
Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
