A NULL pointer dereference vulnerability exists in HDF5. The issue arises when processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field, which may cause the application to crash when the attribute is read. This vulnerability affects HDF5 deployments in various environments, potentially leading to application crashes or security issues. Developers and users [truncated]
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free. This vulnerability could potentially lead to denial-of-service or code execution attacks. Users should review the official CVE record and NVD details for specific affected versions and mitigation strategies.