GHSA-r5m4-5vww-w9f5

Suggest an improvement
Source
https://github.com/advisories/GHSA-r5m4-5vww-w9f5
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-r5m4-5vww-w9f5/GHSA-r5m4-5vww-w9f5.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r5m4-5vww-w9f5
Aliases
Downstream
CGA (18)
JLSEC (1)
Published
2026-05-10T00:33:21Z
Modified
2026-09-10T03:50:55Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
OSGeo gdal has a heap-based buffer overflow
Details

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-based buffer overflow. The attack requires local access. The exploit has been published and may be used. Upgrading to version 3.13.0RC1 addresses this issue. This patch commit sha is 3e04c0385630e4d42517046d9a4967dfccfeb7fd. The affected component should be upgraded.

Database specific
{
    "cwe_ids":  [
        "CWE-119",
        "CWE-125"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-29T22:23:28Z",
    "nvd_published_at":  "2026-05-09T23:16:33Z",
    "severity":  "LOW"
}
References

Affected packages

PyPI / gdal

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.13.0RC1

Affected versions

1.*
1.5.0
1.5.2
1.6.0
1.6.1
1.7.0
1.7.1
1.8.1
1.9.0
1.9.1
1.10.0
1.11.0
1.11.1
1.11.2
2.*
2.0.0
2.0.1
2.1.0
2.1.3
2.2.0
2.2.1
2.2.2
2.2.3
2.2.4
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0
2.4.2
2.4.3
2.4.4
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.2.0
3.2.1
3.2.2
3.2.2.1
3.2.3
3.3.0
3.3.1
3.3.2
3.3.3
3.4.0
3.4.1
3.4.2
3.4.3
3.5.0
3.5.0.3
3.5.1
3.5.2
3.5.3
3.6.0
3.6.0.1
3.6.1
3.6.2
3.6.3
3.6.4
3.7.0
3.7.1
3.7.1.1
3.7.2
3.7.3
3.8.0
3.8.1
3.8.2
3.8.3
3.8.4
3.8.5
3.9.0
3.9.1
3.9.2
3.9.3
3.10.0
3.10.1
3.10.2
3.10.3
3.11.0
3.11.1
3.11.2
3.11.3
3.11.4
3.11.5
3.12.0.post1
3.12.1
3.12.2
3.12.3
3.12.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-r5m4-5vww-w9f5/GHSA-r5m4-5vww-w9f5.json"