{"id":"OSV-2024-390","summary":"Heap-buffer-overflow in H5O__cache_chk_serialize","details":"OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67889\n\n```\nCrash type: Heap-buffer-overflow READ {*}\nCrash state:\nH5O__cache_chk_serialize\nH5C__generate_image\nH5C__flush_single_entry\n```\n","modified":"2025-03-18T00:44:44.672358Z","published":"2024-04-30T00:14:19.116132Z","references":[{"type":"REPORT","url":"https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=67889"}],"affected":[{"package":{"name":"hdf5","ecosystem":"OSS-Fuzz","purl":"pkg:generic/hdf5"},"ranges":[{"type":"GIT","repo":"https://github.com/HDFGroup/hdf5","events":[{"introduced":"966454aac1231da7209ef81c11055d3312181f99"},{"introduced":"04f0647727677d716a3c1c772d35a660a8ea0dc5"},{"introduced":"5a0ec52099cf02224a4066b158bcf1a34829db20"},{"introduced":"f527239564fc27a6e666ce734b88e4ab18765efc"},{"fixed":"85bef9d1a71c0345f7204e4ad56bfc95b8aaca39"}]}],"versions":["1.14.1","hdf5-1_10_10","hdf5-1_10_11","hdf5-1_12_3","hdf5-1_14_1","hdf5-1_14_1-2","hdf5-1_14_2","hdf5-1_14_3","hdf5-1_14_3-rc1","hdf5_1.14.4","hdf5_1.14.4.1","hdf5_1.14.4.2","hdf5_1.14.4.3","hdf5_1.14.5","snapshot","snapshot-1.10","snapshot-1.12","snapshot-1.14","snapshot-1.16","hdf5-1.14.5","hdf5-1.14.6","hdf5_1.14.6","hdff5-1_14-_0","hdff5-1_14_0"],"ecosystem_specific":{"severity":"MEDIUM"},"database_specific":{"fixed_range":"ed082ac981a23eea56d7e15f1bc1fd2d6f9dd5bd:85bef9d1a71c0345f7204e4ad56bfc95b8aaca39","source":"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/hdf5/OSV-2024-390.yaml"}}],"schema_version":"1.7.3"}