<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T17:37:11.243888+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-08102</id>
    <title>cnvd-2025-08102</title>
    <updated>2026-10-03T17:37:11.251416+00:00</updated>
    <content>cnvd-2025-08102</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-08102"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-248387</id>
    <title>EUVD-2026-248387</title>
    <updated>2026-10-03T17:37:11.251449+00:00</updated>
    <content>EUVD-2026-248387</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-248387"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-2913</id>
    <title>fkie_cve-2025-2913</title>
    <updated>2026-10-03T17:37:11.251463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5FL__blk_gc_list of the file src/H5FL.c. The manipulation of the argument H5FL_blk_head_t leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-2913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-v5x4-36wq-jqfc</id>
    <title>GHSA-v5x4-36wq-jqfc</title>
    <updated>2026-10-03T17:37:11.251491+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A vulnerability was found in HDF5 up to 1.14.6. It has been rated as problematic. Affected by this issue is the function H5FL__blk_gc_list of the file src/H5FL.c. The manipulation of the argument H5FL_blk_head_t leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-v5x4-36wq-jqfc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-2913</id>
    <title>msrc_CVE-2025-2913 — HDF5 H5FL.c H5FL__blk_gc_list use after free</title>
    <updated>2026-10-03T17:37:11.251508+00:00</updated>
    <content>msrc_CVE-2025-2913</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-2913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2026-1131</id>
    <title>OESA-2026-1131 — hdf5 security update</title>
    <updated>2026-10-03T17:37:11.251523+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP3: hdf5</p>
<p>HDF5 is a data model, library, and file format for storing and managing data. It supports an unlimited variety of datatypes, and is designed for flexible and efficient I/O and for high volume and complex data. HDF5 is portable and is extensible, allowing applications to evolve in their use of HDF5. The HDF5 Technology suite includes tools and applications for managing, manipulating, viewing, and analyzing data in the HDF5 format.

Security Fix(es):</p>
<p>A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.(CVE-2025-2153)</p>
<p>A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.(CVE-2025-2310)</p>
<p>A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to hea…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2026-1131"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-2913</id>
    <title>UBUNTU-CVE-2025-2913</title>
    <updated>2026-10-03T17:37:11.251577+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: hdf5, Ubuntu:Pro:16.04:LTS: hdf5, Ubuntu:Pro:18.04:LTS: hdf5, Ubuntu:Pro:20.04:LTS: hdf5, Ubuntu:22.04:LTS: hdf5, Ubuntu:24.04:LTS: hdf5, Ubuntu:25.10: hdf5, Ubuntu:26.04:LTS: hdf5</p>
<p>A vulnerability was found in HDF5 up to 1.14.6. It has been rated as critical. Affected by this issue is the function H5FL__blk_gc_list of the file src/H5FL.c. The manipulation of the argument H5FL_blk_head_t leads to use after free. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-2913"/>
  </entry>
</feed>
