Medium severity5.3NVD Advisory· Published Mar 14, 2025· Updated Jun 17, 2026
CVE-2025-2310
CVE-2025-2310
Description
A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- HDF5/HDF5description
Patches
Vulnerability mechanics
References
4- github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc4.mdnvdExploitThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
News mentions
0No linked articles in our index yet.