CVE-2024-32624
NixOS vulnerability analysis and mitigation

Overview

HDF5 Library through version 1.14.3 contains a heap-based buffer overflow vulnerability in the H5Trefmemsetnull function within H5Tref.c (called from H5Tconv_ref in H5Tconv.c), which results in the corruption of the instruction pointer (NVD). The vulnerability was discovered and disclosed in May 2024, affecting all versions of the HDF5 Library up to and including version 1.14.3, and has been fixed in version 1.14.4 (HDF Group).

Technical details

The vulnerability is classified as a heap-based buffer overflow (CWE-122) with a CVSS v3.1 base score of 7.4 (HIGH). The attack vector is network-based (AV:N) with high attack complexity (AC:H), requires no privileges (PR:N) or user interaction (UI:N), and has a scope that is unchanged (S:U). The impact includes high confidentiality (C:H) and integrity (I:H) risks, but no availability impact (A:N) (NVD).

Impact

The vulnerability can lead to the corruption of the instruction pointer, which could potentially allow attackers to execute arbitrary code or cause denial of service conditions. The high confidentiality and integrity impact ratings suggest that successful exploitation could result in significant unauthorized information disclosure and data manipulation (NVD).

Mitigation and workarounds

The vulnerability has been fixed in HDF5 version 1.14.4, released on April 15, 2024. Users are advised to upgrade to this version to mitigate the risk (HDF Group).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management