A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-19480 A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 09 Jul 2025 00:00:00 +0900

Type Values Removed Values Added
First Time appeared Hdfgroup
Hdfgroup hdf5
CPEs cpe:2.3:a:hdfgroup:hdf5:1.14.6:*:*:*:*:*:*:*
Vendors & Products Hdfgroup
Hdfgroup hdf5

Tue, 01 Jul 2025 01:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Jun 2025 21:30:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Sun, 29 Jun 2025 19:15:00 +0900

Type Values Removed Values Added
Description A vulnerability has been found in HDF5 1.14.6 and classified as problematic. Affected by this vulnerability is the function H5G__node_cmp3 of the file src/H5Gnode.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Title HDF5 H5Gnode.c H5G__node_cmp3 stack-based overflow
Weaknesses CWE-119
CWE-121
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-06-30T15:49:20.682Z

Reserved: 2025-06-28T10:42:53.841Z

Link: CVE-2025-6857

cve-icon Vulnrichment

Updated: 2025-06-30T15:49:13.939Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-29T10:15:22.800

Modified: 2025-07-08T14:39:20.493

Link: CVE-2025-6857

cve-icon Redhat

Severity : Low

Publid Date: 2025-06-29T10:00:18Z

Links: CVE-2025-6857 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2025-07-07T07:16:30Z

Weaknesses