<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 10:57:05 +0000</lastBuildDate>
    <item>
      <title>cnvd-2025-18668</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-18668</link>
      <description>cnvd-2025-18668</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-18668</guid>
    </item>
    <item>
      <title>EUVD-2026-238396</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-238396</link>
      <description>EUVD-2026-238396</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-238396</guid>
    </item>
    <item>
      <title>fkie_cve-2025-2310</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-2310</link>
      <description>&lt;p&gt;A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-2310</guid>
    </item>
    <item>
      <title>GHSA-qxwf-xj2v-qm83</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-qxwf-xj2v-qm83</link>
      <description>&lt;p&gt;A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor was contacted early about a batch of vulnerabilities. His response was &amp;#34;reject&amp;#34; without further explanation. We have not received an elaboration even after asking politely for further details. Currently we assume that the vendor wants to &amp;#34;dispute&amp;#34; the entries which is why they are flagged as such until further details become available.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The real existence of this vulnerability is still doubted at the moment. The vendor was contacted early about a batch of vulnerabilities. His response was &amp;#34;reject&amp;#34; without further explanation. We have not received an elaboration even after asking politely for further details. Currently we assume that the vendor wants to &amp;#34;dispute&amp;#34; the entries which is why they are flagged as such until further details become available.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-qxwf-xj2v-qm83</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-2310 — HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-2310</link>
      <description>msrc_CVE-2025-2310</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-2310</guid>
    </item>
    <item>
      <title>OESA-2026-1131 — hdf5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1131</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: hdf5&lt;/p&gt;
&lt;p&gt;HDF5 is a data model, library, and file format for storing and managing data. It supports an unlimited variety of datatypes, and is designed for flexible and efficient I/O and for high volume and complex data. HDF5 is portable and is extensible, allowing applications to evolve in their use of HDF5. The HDF5 Technology suite includes tools and applications for managing, manipulating, viewing, and analyzing data in the HDF5 format.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.(CVE-2025-2153)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.(CVE-2025-2310)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to hea…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP3: hdf5&lt;/p&gt;
&lt;p&gt;HDF5 is a data model, library, and file format for storing and managing data. It supports an unlimited variety of datatypes, and is designed for flexible and efficient I/O and for high volume and complex data. HDF5 is portable and is extensible, allowing applications to evolve in their use of HDF5. The HDF5 Technology suite includes tools and applications for managing, manipulating, viewing, and analyzing data in the HDF5 format.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;A vulnerability, which was classified as critical, was found in HDF5 1.14.6. Affected is the function H5SM_delete of the file H5SM.c of the component h5 File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used.(CVE-2025-2153)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.(CVE-2025-2310)&lt;/p&gt;
&lt;p&gt;A vulnerability was found in HDF5 up to 1.14.6. It has been declared as problematic. Affected by this vulnerability is the function H5O_msg_flush of the file src/H5Omessage.c. The manipulation of the argument oh leads to hea…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1131</guid>
    </item>
    <item>
      <title>RHSA-2025:23731 — Red Hat Security Advisory: RHEL AI 3.0 hdf5 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:23731</link>
      <description>&lt;p&gt;HDF5: HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow hdf5: HDF5 heap-based overflow hdf5: HDF5 heap-based overflow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;HDF5: HDF5 Metadata Attribute Decoder H5MM_strndup heap-based overflow hdf5: HDF5 heap-based overflow hdf5: HDF5 heap-based overflow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:23731</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-2310</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-2310</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: hdf5, Ubuntu:Pro:16.04:LTS: hdf5, Ubuntu:Pro:18.04:LTS: hdf5, Ubuntu:Pro:20.04:LTS: hdf5, Ubuntu:22.04:LTS: hdf5, Ubuntu:24.04:LTS: hdf5, Ubuntu:25.10: hdf5, Ubuntu:26.04:LTS: hdf5&lt;/p&gt;
&lt;p&gt;A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: hdf5, Ubuntu:Pro:16.04:LTS: hdf5, Ubuntu:Pro:18.04:LTS: hdf5, Ubuntu:Pro:20.04:LTS: hdf5, Ubuntu:22.04:LTS: hdf5, Ubuntu:24.04:LTS: hdf5, Ubuntu:25.10: hdf5, Ubuntu:26.04:LTS: hdf5&lt;/p&gt;
&lt;p&gt;A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-2310</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2907 — Red Hat Enterprise Linux AI (HDF5 ): Mehrere Schwachstellen ermöglichen Manipulation von Dateien</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2907</link>
      <description>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux AI ausnutzen, um Dateien zu manipulieren, was möglicherweise die Ausführung von beliebigem Code oder einen Denial-of-Service-Zustand ermöglicht.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein lokaler Angreifer kann mehrere Schwachstellen in Red Hat Enterprise Linux AI ausnutzen, um Dateien zu manipulieren, was möglicherweise die Ausführung von beliebigem Code oder einen Denial-of-Service-Zustand ermöglicht.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2907</guid>
    </item>
  </channel>
</rss>
