<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
	<DocumentTitle xml:lang="en">An update for hdf5 is now available for openEuler-24.03-LTS-SP3</DocumentTitle>
	<DocumentType>Security Advisory</DocumentType>
	<DocumentPublisher Type="Vendor">
		<ContactDetails>openeuler-security@openeuler.org</ContactDetails>
		<IssuingAuthority>openEuler security committee</IssuingAuthority>
	</DocumentPublisher>
	<DocumentTracking>
		<Identification>
			<ID>openEuler-SA-2026-3874</ID>
		</Identification>
		<Status>Final</Status>
		<Version>1.0</Version>
		<RevisionHistory>
			<Revision>
				<Number>1.0</Number>
				<Date>2026-09-20</Date>
				<Description>Initial</Description>
			</Revision>
		</RevisionHistory>
		<InitialReleaseDate>2026-09-20</InitialReleaseDate>
		<CurrentReleaseDate>2026-09-20</CurrentReleaseDate>
		<Generator>
			<Engine>openEuler SA Tool V1.0</Engine>
			<Date>2026-09-20</Date>
		</Generator>
	</DocumentTracking>
	<DocumentNotes>
		<Note Title="Synopsis" Type="General" Ordinal="1" xml:lang="en">hdf5 security update</Note>
		<Note Title="Summary" Type="General" Ordinal="2" xml:lang="en">An update for hdf5 is now available for openEuler-24.03-LTS-SP3</Note>
		<Note Title="Description" Type="General" Ordinal="3" xml:lang="en">HDF5 is a data model, library, and file format for storing and managing data. It supports an unlimited variety of datatypes, and is designed for flexible and efficient I/O and for high volume and complex data. HDF5 is portable and is extensible, allowing applications to evolve in their use of HDF5. The HDF5 Technology suite includes tools and applications for managing, manipulating, viewing, and analyzing data in the HDF5 format.

Security Fix(es):

A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__accum_free of the file src/H5Faccum.c. The manipulation of the argument overlap_size leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.(CVE-2025-2915)

A critical vulnerability has been identified in HDF5 up to version 1.14.6. The issue affects the H5FS__sect_find_node function in the H5FSsection.c file, leading to a heap-based buffer overflow. The attack can be launched on the local host. The exploit has been publicly disclosed and may be in use.(CVE-2025-6270)

A vulnerability, classified as problematic, has been identified in HDF5 1.14.6. This issue affects the H5C__load_entry function in the file /src/H5Centry.c, leading to resource consumption. The attack requires local access. The exploit has been publicly disclosed and may be used.(CVE-2025-6817)

A vulnerability classified as problematic was found in HDF5 1.14.6, affecting the H5FS__sect_link_size function in the file src/H5FSsection.c. The manipulation leads to a heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.(CVE-2025-7069)

H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&apos;s stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.(CVE-2026-19025)</Note>
		<Note Title="Topic" Type="General" Ordinal="4" xml:lang="en">An update for hdf5 is now available for master/openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP4/openEuler-24.03-LTS-Next/openEuler-24.03-LTS-SP1/openEuler-24.03-LTS-SP3/openEuler-24.03-LTS-SP4.

openEuler Security has rated this update as having a security impact of medium. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.</Note>
		<Note Title="Severity" Type="General" Ordinal="5" xml:lang="en">Medium</Note>
		<Note Title="Affected Component" Type="General" Ordinal="6" xml:lang="en">hdf5</Note>
	</DocumentNotes>
	<DocumentReferences>
		<Reference Type="Self">
			<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3874</URL>
		</Reference>
		<Reference Type="openEuler CVE">
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-2915</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-6270</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-6817</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2025-7069</URL>
			<URL>https://www.openeuler.org/en/security/cve/detail/?cveId=CVE-2026-19025</URL>
		</Reference>
		<Reference Type="Other">
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2025-2915</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2025-6270</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2025-6817</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2025-7069</URL>
			<URL>https://nvd.nist.gov/vuln/detail/CVE-2026-19025</URL>
		</Reference>
	</DocumentReferences>
	<ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
		<Branch Type="Product Name" Name="openEuler">
			<FullProductName ProductID="openEuler-24.03-LTS-SP3" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">openEuler-24.03-LTS-SP3</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="aarch64">
			<FullProductName ProductID="hdf5-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-debuginfo-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-debuginfo-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-debugsource-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-debugsource-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-devel-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-devel-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-mpich-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-mpich-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-mpich-devel-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-mpich-devel-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-mpich-static-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-mpich-static-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-openmpi-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-openmpi-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-openmpi-devel-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-openmpi-devel-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-openmpi-static-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-openmpi-static-1.14.5-7.oe2403sp3.aarch64.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="src">
			<FullProductName ProductID="hdf5-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-1.14.5-7.oe2403sp3.src.rpm</FullProductName>
		</Branch>
		<Branch Type="Package Arch" Name="x86_64">
			<FullProductName ProductID="hdf5-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-debuginfo-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-debuginfo-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-debugsource-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-debugsource-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-devel-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-devel-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-mpich-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-mpich-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-mpich-devel-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-mpich-devel-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-mpich-static-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-mpich-static-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-openmpi-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-openmpi-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-openmpi-devel-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-openmpi-devel-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
			<FullProductName ProductID="hdf5-openmpi-static-1.14.5-7" CPE="cpe:/a:openEuler:openEuler:24.03-LTS-SP3">hdf5-openmpi-static-1.14.5-7.oe2403sp3.x86_64.rpm</FullProductName>
		</Branch>
	</ProductTree>
	<Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability classified as problematic was found in HDF5 up to 1.14.6. This vulnerability affects the function H5F__accum_free of the file src/H5Faccum.c. The manipulation of the argument overlap_size leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.</Note>
		</Notes>
		<ReleaseDate>2026-09-20</ReleaseDate>
		<CVE>CVE-2025-2915</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Low</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>3.3</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>hdf5 security update</Description>
				<DATE>2026-09-20</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3874</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A critical vulnerability has been identified in HDF5 up to version 1.14.6. The issue affects the H5FS__sect_find_node function in the H5FSsection.c file, leading to a heap-based buffer overflow. The attack can be launched on the local host. The exploit has been publicly disclosed and may be in use.</Note>
		</Notes>
		<ReleaseDate>2026-09-20</ReleaseDate>
		<CVE>CVE-2025-6270</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>5.3</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>hdf5 security update</Description>
				<DATE>2026-09-20</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3874</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability, classified as problematic, has been identified in HDF5 1.14.6. This issue affects the H5C__load_entry function in the file /src/H5Centry.c, leading to resource consumption. The attack requires local access. The exploit has been publicly disclosed and may be used.</Note>
		</Notes>
		<ReleaseDate>2026-09-20</ReleaseDate>
		<CVE>CVE-2025-6817</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Low</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>3.3</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>hdf5 security update</Description>
				<DATE>2026-09-20</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3874</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability classified as problematic was found in HDF5 1.14.6, affecting the H5FS__sect_link_size function in the file src/H5FSsection.c. The manipulation leads to a heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.</Note>
		</Notes>
		<ReleaseDate>2026-09-20</ReleaseDate>
		<CVE>CVE-2025-7069</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Low</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>3.3</BaseScore>
				<Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>hdf5 security update</Description>
				<DATE>2026-09-20</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3874</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
	<Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
		<Notes>
			<Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset&apos;s stored chunk-layout dimensionality matches its dataspace rank when an existing dataset is opened, whereas this check is performed only at dataset-creation time. This allows attackers to cause a denial of service (divide-by-zero and application crash in H5S__hyper_iter_get_seq_list in src/H5Shyper.c) via a crafted HDF5 file with mismatched chunk/dataspace ranks that is opened and read via H5Dopen2 and H5Dread, e.g. by the h5repack tool.</Note>
		</Notes>
		<ReleaseDate>2026-09-20</ReleaseDate>
		<CVE>CVE-2026-19025</CVE>
		<ProductStatuses>
			<Status Type="Fixed">
				<ProductID>openEuler-24.03-LTS-SP3</ProductID>
			</Status>
		</ProductStatuses>
		<Threats>
			<Threat Type="Impact">
				<Description>Medium</Description>
			</Threat>
		</Threats>
		<CVSSScoreSets>
			<ScoreSet>
				<BaseScore>6.8</BaseScore>
				<Vector>AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X</Vector>
			</ScoreSet>
		</CVSSScoreSets>
		<Remediations>
			<Remediation Type="Vendor Fix">
				<Description>hdf5 security update</Description>
				<DATE>2026-09-20</DATE>
				<URL>https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3874</URL>
			</Remediation>
		</Remediations>
	</Vulnerability>
</cvrfdoc>