CVE-2025-2310 | HDF5 1.14.6 Metadata Attribute Decoder H5MM_strndup heap-based overflow
A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2025-2310. Attacking locally is a requirement. Furthermore, there is an exploit available.
The vendor plans to fix this issue in an upcoming release.