OSV-2024-390

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/hdf5/OSV-2024-390.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2024-390
Published
2024-04-30T00:14:19.116132Z
Modified
2025-03-18T00:44:44.672358Z
Summary
Heap-buffer-overflow in H5O__cache_chk_serialize
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67889

Crash type: Heap-buffer-overflow READ {*}
Crash state:
H5O__cache_chk_serialize
H5C__generate_image
H5C__flush_single_entry
References

Affected packages

OSS-Fuzz / hdf5

Package

Name
hdf5
Purl
pkg:generic/hdf5

Affected versions

1.*

1.14.1

hdf5-1.*

hdf5-1.14.5
hdf5-1.14.6

Other

hdf5-1_10_10
hdf5-1_10_11
hdf5-1_12_3
hdf5-1_14_1
hdf5-1_14_1-2
hdf5-1_14_2
hdf5-1_14_3
hdf5-1_14_3-rc1
hdff5-1_14-_0
hdff5-1_14_0
snapshot

hdf5_1.*

hdf5_1.14.4
hdf5_1.14.4.1
hdf5_1.14.4.2
hdf5_1.14.4.3
hdf5_1.14.5
hdf5_1.14.6

snapshot-1.*

snapshot-1.10
snapshot-1.12
snapshot-1.14
snapshot-1.16

Ecosystem specific

{
    "severity": "MEDIUM"
}

Database specific

{
    "fixed_range": "ed082ac981a23eea56d7e15f1bc1fd2d6f9dd5bd:85bef9d1a71c0345f7204e4ad56bfc95b8aaca39"
}