HomeDefectsLIN1024-893
Fixed

LIN1024-893 : Security Advisory - hdf5 - CVE-2024-32605

Created: May 12, 2024    Updated: Sep 15, 2024
Resolved Date: Aug 19, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_memcpyvv in H5VM.c (called from H5D__compact_readvv in H5Dcompact.c).

CREATE(Triage):(User=admin) CVE-2024-32605 (https://nvd.nist.gov/vuln/detail/CVE-2024-32605)

CVEs