<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:05:05.479524+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-18668</id>
    <title>cnvd-2025-18668</title>
    <updated>2026-10-03T04:05:05.523007+00:00</updated>
    <content>cnvd-2025-18668</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-18668"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-238396</id>
    <title>EUVD-2026-238396</title>
    <updated>2026-10-03T04:05:05.523046+00:00</updated>
    <content>EUVD-2026-238396</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-238396"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-2310</id>
    <title>fkie_cve-2025-2310</title>
    <updated>2026-10-03T04:05:05.523060+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-2310"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qxwf-xj2v-qm83</id>
    <title>GHSA-qxwf-xj2v-qm83</title>
    <updated>2026-10-03T04:05:05.523090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor was contacted early about a batch of vulnerabilities. His response was "reject" without further explanation. We have not received an elaboration even after asking politely for further details. Currently we assume that the vendor wants to "dispute" the entries which is why they are flagged as such until further details become available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qxwf-xj2v-qm83"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-2310</id>
    <title>msrc_CVE-2025-2310 — HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow</title>
    <updated>2026-10-03T04:05:05.523110+00:00</updated>
    <content>msrc_CVE-2025-2310</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-2310"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1131</id>
    <title>OESA-2026-1131 — hdf5 security update</title>
    <updated>2026-10-03T04:05:05.523129+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: hdf5</p>
<p>HDF5 is a data model, library, and file format for storing and managing data. It supports an unlimited variety of datatypes, and is designed for flexible and efficient I/O and for high volume and complex data. HDF5 is portable and is extensible, allowing applications to evolve in their use of HDF5. The HDF5 Technology suite includes tools and applications for managing, manipulating, viewing, and analyzing data in the HDF5 format.

Security Fix(es):</p>
<p>A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.(CVE-2025-2153)</p>
<p>A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.(CVE-2025-2310)</p>
<p>A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to hea…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:23731</id>
    <title>RHSA-2025:23731 — Red Hat Security Advisory: RHEL AI 3.0 hdf5 security update</title>
    <updated>2026-10-03T04:05:05.523184+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>HDF5: HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow hdf5: HDF5 heap-based overflow hdf5: HDF5 heap-based overflow</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:23731"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-2310</id>
    <title>UBUNTU-CVE-2025-2310</title>
    <updated>2026-10-03T04:05:05.523205+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: hdf5, Ubuntu:Pro:16.04:LTS: hdf5, Ubuntu:Pro:18.04:LTS: hdf5, Ubuntu:Pro:20.04:LTS: hdf5, Ubuntu:22.04:LTS: hdf5, Ubuntu:24.04:LTS: hdf5, Ubuntu:25.10: hdf5, Ubuntu:26.04:LTS: hdf5</p>
<p>A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-2310"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2907</id>
    <title>WID-SEC-W-2025-2907 — Red Hat Enterprise Linux AI (HDF5 ): Mehrere Schwachstellen ermöglichen Manipulation von Dateien</title>
    <updated>2026-10-03T04:05:05.523247+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux AI ausnutzen, um Dateien zu manipulieren, was möglicherweise die Ausführung von beliebigem Code oder einen Denial-of-Service-Zustand ermöglicht.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2907"/>
  </entry>
</feed>
