HomeDefectsLIN1024-908
Fixed

LIN1024-908 : Security Advisory - hdf5 - CVE-2024-32620

Created: May 12, 2024    Updated: Sep 15, 2024
Resolved Date: Aug 19, 2024
Found In Version: 10.24.33.1
Fix Version: 10.24.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Userspace

Description

HDF5 Library through 1.14.3 contains a heap-based buffer over-read in H5F_addr_decode_len in H5Fint.c, resulting in the corruption of the instruction pointer.

CREATE(Triage):(User=admin) CVE-2024-32620 (https://nvd.nist.gov/vuln/detail/CVE-2024-32620)

CVEs