Bug 2375414 (CVE-2025-6856) - CVE-2025-6856 hdf5: HDF5 Use-After-Free Vulnerability
Summary: CVE-2025-6856 hdf5: HDF5 Use-After-Free Vulnerability
Keywords:
Status: NEW
Alias: CVE-2025-6856
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2375493 2375498 2375502 2375509 2375511
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-06-29 10:01 UTC by OSIDB Bzimport
Modified: 2025-06-30 13:12 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-06-29 10:01:10 UTC
A vulnerability, which was classified as problematic, was found in HDF5 1.14.6. Affected is the function H5FL__reg_gc_list of the file src/H5FL.c. The manipulation leads to use after free. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.


Note You need to log in before you can comment on or make changes to this bug.