Search
Search is not available in local development.
Run npx pagefind --site __site after building to enable it.
JLSEC-2026-326

JLSEC-2026-326

JLSEC Published
Modified
Affected Packages
HDF5_jll >= 1.14.5+0, < 2.0.0+0
Aliases / Upstream
CVE-2025-2308

A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffsetdecompressone_byte of the component Scale-Offset Filter. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.

References