CVE-2024-32606
NixOS vulnerability analysis and mitigation

Overview

HDF5 Library through version 1.14.3 contains a vulnerability where it may attempt to dereference uninitialized values in the h5tools_str_sprint function located in tools/lib/h5tools_str.c, which is called from h5tools_dump_simple_data in tools/lib/h5tools_dump.c. The vulnerability was discovered and disclosed in May 2024, affecting all versions of HDF5 Library up to and including version 1.14.3 (HDF Group).

Technical details

The vulnerability has been assigned a CVSS v3.1 Base Score of 5.7 (MEDIUM) with the following vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H. The issue is classified under CWE-908 (Use of Uninitialized Resource). The vulnerability specifically involves the potential dereferencing of uninitialized values in the h5tools_str_sprint function, which is called during data dumping operations (NVD).

Impact

The vulnerability can lead to potential security issues when processing HDF5 files, particularly during data dumping operations. The CVSS scoring indicates that while confidentiality impact is none, there is a low impact on integrity and a high impact on availability, suggesting that the primary risk is to system stability and reliability (NVD).

Exploitability

The vulnerability requires local access (AV:L) and has high attack complexity (AC:H), but requires no privileges (PR:N) or user interaction (UI:N). The scope is unchanged (S:U), indicating that the vulnerability can only affect resources managed by the same security authority (NVD).

Mitigation and workarounds

The vulnerability has been fixed in HDF5 version 1.14.4, released on April 15, 2024. Users are advised to upgrade to this version to address this and several other security issues. The fix is part of a larger security update that addresses multiple CVEs discovered through fuzzing HDF5 files (HDF Group).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-34191CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-32327CRITICAL9.1
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34502HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2026-34501HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026
CVE-2025-49506HIGH7.5
  • NixOS logoNixOS
  • apr-util
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management