A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5FL__malloc of the file src/H5FL.c. The manipulation leads to memory leak. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Link | Tags |
---|---|
https://vuldb.com/?id.314903 | technical description vdb entry third party advisory |
https://vuldb.com/?ctiid.314903 | permissions required signature |
https://vuldb.com/?submit.602537 | vdb entry third party advisory |
https://github.com/HDFGroup/hdf5/issues/5578 | third party advisory exploit issue tracking |
https://github.com/user-attachments/files/20623530/hdf5_crash_10.txt | exploit |