A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation leads to resource consumption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
History

Tue, 01 Jul 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Hdfgroup
Hdfgroup hdf5
CPEs cpe:2.3:a:hdfgroup:hdf5:1.14.6:*:*:*:*:*:*:*
Vendors & Products Hdfgroup
Hdfgroup hdf5

Mon, 30 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 30 Jun 2025 12:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Sat, 28 Jun 2025 11:45:00 +0000

Type Values Removed Values Added
Description A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation leads to resource consumption. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.
Title HDF5 H5Centry.c H5C__load_entry resource consumption
Weaknesses CWE-400
CWE-404
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-06-28T11:31:05.770Z

Updated: 2025-06-30T16:06:39.966Z

Reserved: 2025-06-27T16:52:24.855Z

Link: CVE-2025-6817

cve-icon Vulnrichment

Updated: 2025-06-30T16:06:30.764Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-28T12:15:20.790

Modified: 2025-07-01T17:30:53.610

Link: CVE-2025-6817

cve-icon Redhat

Severity : Low

Publid Date: 2025-06-28T11:31:05Z

Links: CVE-2025-6817 - Bugzilla