OSV-2023-392

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/hdf5/OSV-2023-392.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2023-392
Published
2023-05-13T14:00:26.093088Z
Modified
2026-06-25T14:38:38.679394Z
Summary
Negative-size-param in H5MM_memcpy
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=58892

Crash type: Negative-size-param
Crash state:
H5MM_memcpy
H5O__link_decode
H5O__msg_iterate_real
References

Affected packages

OSS-Fuzz / hdf5

Package

Name
hdf5
Purl
pkg:generic/hdf5

Affected ranges

Affected versions

1.*
1.14.1
2.*
2.0.0
2.1.0
2.1.0-pre1test
2.1.1
Other
final_autotools_develop
hdf5-1_10_10
hdf5-1_10_11
hdf5-1_12_3
hdf5-1_14_1
hdf5-1_14_1-2
hdf5-1_14_2
hdf5-1_14_3
hdf5-1_14_3-rc1
hdff5-1_14-_0
hdff5-1_14_0
snapshot
hdf5-1.*
hdf5-1.14.4.1
hdf5-1.14.5
hdf5-1.14.6
hdf5_1.*
hdf5_1.14.4
hdf5_1.14.4.1
hdf5_1.14.4.2
hdf5_1.14.4.3
hdf5_1.14.5
hdf5_1.14.6
hdf5_2.*
hdf5_2.0.0
hdf5_2.1.0
snapshot-1.*
snapshot-1.10
snapshot-1.12
snapshot-1.14
snapshot-1.16
temp-1.*
temp-1.14.4-3
test-2.*
test-2.0.1-pre1

Ecosystem specific

{
    "severity": null
}

Database specific

source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/hdf5/OSV-2023-392.yaml"