CVE-2025-2925

LOW

HDF5 < 1.14.6 - Use-After-Free in H5MM_realloc

Title source: llm
STIX 2.1

Description

A vulnerability has been found in HDF5 up to 1.14.6 and classified as problematic. This vulnerability affects the function H5MM_realloc of the file src/H5MM.c. The manipulation of the argument mem leads to double free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.301900
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.301900
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.521193
Exploit, Issue Tracking, Third Party Advisory exploit issue-tracking
https://github.com/HDFGroup/hdf5/issues/5383

Scores

CVSS v3 3.3
EPSS 0.0021
EPSS Percentile 10.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-415
Status published
Products (1)
hdfgroup/hdf5 < 1.14.6
Published Mar 28, 2025
Tracked Since Feb 18, 2026