[Git][security-tracker-team/security-tracker][master] Update status for some hdf5 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 6 06:40:23 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b5c1c7eb by Salvatore Bonaccorso at 2026-08-06T07:40:07+02:00
Update status for some hdf5 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7612,7 +7612,7 @@ CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability. Processi
[bullseye] - hdf5 <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc (2.2.0-rc1)
CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library. Proces ...)
- - hdf5 <unfixed> (bug #1143000)
+ - hdf5 2.1.0+repack-1 (bug #1143000)
[bookworm] - hdf5 <postponed> (Minor issue)
[bullseye] - hdf5 <postponed> (Minor issue)
NOTE: https://github.com/HDFGroup/hdf5/issues/6124
@@ -15349,7 +15349,7 @@ CVE-2026-26199 (HDF5 is a high-performance library and a file format specificati
NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
TODO: isolate fixing commit
CVE-2026-26197 (HDF5 is a high-performance library and a file format specification tha ...)
- - hdf5 <unfixed> (bug #1143002)
+ - hdf5 2.1.0+repack-1 (bug #1143002)
[bookworm] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
[bullseye] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f
@@ -196437,10 +196437,10 @@ CVE-2025-7069 (A vulnerability, which was classified as problematic, was found i
NOTE: https://github.com/HDFGroup/hdf5/issues/5550
NOTE: Negligible security impact
CVE-2025-7068 (A vulnerability, which was classified as problematic, has been found i ...)
- - hdf5 <unfixed> (bug #1108885; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1108885; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5578
NOTE: https://github.com/HDFGroup/hdf5/pull/5817
- NOTE: https://github.com/HDFGroup/hdf5/commit/7dd110251d67b2c8cfe48d2e7a0b21a2e0c06432
+ NOTE: https://github.com/HDFGroup/hdf5/commit/7dd110251d67b2c8cfe48d2e7a0b21a2e0c06432 (2.0.0)
NOTE: Negligible security impact
CVE-2025-53605 (The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion ...)
- rust-protobuf 3.7.2-1 (bug #1103833)
@@ -196511,10 +196511,10 @@ CVE-2025-1735 (In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* b
NOTE: https://github.com/php/php-src/security/advisories/GHSA-hrwm-9436-5mv3
NOTE: Fixed by: https://github.com/php/php-src/commit/9376aeef9f8ff81f2705b8016237ec3e30bdee44 (php-8.1.33)
CVE-2025-7067 (A vulnerability classified as problematic was found in HDF5 1.14.6. Th ...)
- - hdf5 <unfixed> (bug #1108886; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1108886; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5577
NOTE: https://github.com/HDFGroup/hdf5/pull/5815
- NOTE: https://github.com/HDFGroup/hdf5/commit/ea4b483d981b1c73ba2b8185c544565e4b05ae0e
+ NOTE: https://github.com/HDFGroup/hdf5/commit/ea4b483d981b1c73ba2b8185c544565e4b05ae0e (2.0.0)
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-7066 (Jirafeau normally prevents browser preview for text files due to the p ...)
NOT-FOR-US: Jirafeau
@@ -198314,10 +198314,10 @@ CVE-2025-6857 (A vulnerability has been found in HDF5 1.14.6 and classified as p
NOTE: https://github.com/HDFGroup/hdf5/issues/5575
NOTE: Negligible security impact
CVE-2025-6856 (A vulnerability, which was classified as problematic, was found in HDF ...)
- - hdf5 <unfixed> (unimportant)
+ - hdf5 2.1.0+repack-1 (unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5574
NOTE: https://github.com/HDFGroup/hdf5/pull/5829
- NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675
+ NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675 (2.0.0)
NOTE: Negligible security impact
CVE-2025-6855 (A vulnerability, which was classified as critical, has been found in c ...)
NOT-FOR-US: Langchain-Chatchat
@@ -198419,10 +198419,10 @@ CVE-2025-53391 (The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through
- zulucrypt <removed> (bug #1108288)
[bullseye] - zulucrypt <end-of-life> (EOL in bullseye LTS)
CVE-2025-6816 (A vulnerability classified as problematic was found in HDF5 1.14.6. Th ...)
- - hdf5 <unfixed> (bug #1108482; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1108482; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5571
NOTE: https://github.com/HDFGroup/hdf5/pull/5829
- NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675
+ NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675 (2.0.0)
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-6778 (A vulnerability, which was classified as problematic, was found in cod ...)
NOT-FOR-US: code-projects
@@ -198861,10 +198861,10 @@ CVE-2025-6752 (A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7
CVE-2025-6751 (A vulnerability, which was classified as critical, was found in Linksy ...)
NOT-FOR-US: Linksys
CVE-2025-6750 (A vulnerability, which was classified as problematic, has been found i ...)
- - hdf5 <unfixed> (bug #1108409; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1108409; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5549
NOTE: https://github.com/HDFGroup/hdf5/pull/5856
- NOTE: https://github.com/HDFGroup/hdf5/commit/86149a098837a37b2513746e9baf84010f75fb54
+ NOTE: https://github.com/HDFGroup/hdf5/commit/86149a098837a37b2513746e9baf84010f75fb54 (2.0.0)
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-6749 (A vulnerability classified as critical was found in huija bicycleShari ...)
NOT-FOR-US: bicycleSharingServer
@@ -199896,10 +199896,10 @@ CVE-2025-6518 (A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It h
CVE-2025-6517 (A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified ...)
NOT-FOR-US: Dromara MaxKey
CVE-2025-6516 (A vulnerability has been found in HDF5 up to 1.14.6 and classified as ...)
- - hdf5 <unfixed> (unimportant)
+ - hdf5 2.1.0+repack-1 (unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5581
NOTE: https://github.com/HDFGroup/hdf5/pull/5756
- NOTE: https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70
+ NOTE: https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70 (2.0.0)
NOTE: Negligible security impact
CVE-2025-6513 (Standard Windows users can access the configuration file for database ...)
NOT-FOR-US: Bizerba
@@ -200746,9 +200746,9 @@ CVE-2025-6270 (A vulnerability, which was classified as critical, has been found
NOTE: https://github.com/HDFGroup/hdf5/issues/5580
NOTE: Negligible security impact
CVE-2025-6269 (A vulnerability classified as critical was found in HDF5 up to 1.14.6. ...)
- - hdf5 <unfixed> (bug #1108155; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1108155; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5579
- NOTE: https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70
+ NOTE: https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70 (2.0.0)
NOTE: Negligible security impact
CVE-2025-6268 (A vulnerability classified as problematic has been found in Luna Imagi ...)
NOT-FOR-US: Luna Imaging
@@ -228560,28 +228560,28 @@ CVE-2025-30211 (Erlang/OTP is a set of libraries for the Erlang programming lang
NOTE: https://github.com/erlang/otp/commit/d64d9fb0688092356a336e38a8717499113312a0 (OTP-25.3.2.19, OTP-26.2.5.10, OTP-27.3.1)
NOTE: https://github.com/erlang/otp/commit/5ee26eb412a76ba1c6afdf4524b62939a48d1bce (OTP-25.3.2.19, OTP-26.2.5.10, OTP-27.3.1)
CVE-2025-2926 (A vulnerability was found in HDF5 up to 1.14.6 and classified as probl ...)
- - hdf5 <unfixed> (bug #1103531; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1103531; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5384
NOTE: https://github.com/HDFGroup/hdf5/pull/5841
- NOTE: https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2
+ NOTE: https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2 (2.0.0)
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-2925 (A vulnerability has been found in HDF5 up to 1.14.6 and classified as ...)
- - hdf5 <unfixed> (bug #1103532; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1103532; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5383
NOTE: https://github.com/HDFGroup/hdf5/pull/5739
- NOTE: https://github.com/HDFGroup/hdf5/commit/4310c19608455c17a213383d07715efb2918defc
+ NOTE: https://github.com/HDFGroup/hdf5/commit/4310c19608455c17a213383d07715efb2918defc (2.0.0)
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-2924 (A vulnerability, which was classified as problematic, was found in HDF ...)
- - hdf5 <unfixed> (bug #1103533; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1103533; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5382
NOTE: https://github.com/HDFGroup/hdf5/pull/5814
- NOTE: https://github.com/HDFGroup/hdf5/commit/0a57195ca67d278f1cf7d01566c121048e337a59
+ NOTE: https://github.com/HDFGroup/hdf5/commit/0a57195ca67d278f1cf7d01566c121048e337a59 (2.0.0)
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-2923 (A vulnerability, which was classified as problematic, has been found i ...)
- - hdf5 <unfixed> (bug #1103534; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1103534; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5381
NOTE: https://github.com/HDFGroup/hdf5/pull/5829
- NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675
+ NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675 (2.0.0)
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-2922 (A vulnerability classified as problematic was found in Netis WF-2404 1 ...)
NOT-FOR-US: Netis
@@ -228596,23 +228596,23 @@ CVE-2025-2917 (A vulnerability, which was classified as problematic, was found i
CVE-2025-2916 (A vulnerability, which was classified as critical, has been found in A ...)
NOT-FOR-US: Aishida Call Center System
CVE-2025-2915 (A vulnerability classified as problematic was found in HDF5 up to 1.14 ...)
- - hdf5 <unfixed> (bug #1103536; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1103536; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5380
NOTE: https://github.com/HDFGroup/hdf5/commit/26a76bafdef3a0950d348a08667de161a19b7c2c
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-2914 (A vulnerability classified as problematic has been found in HDF5 up to ...)
- - hdf5 <unfixed> (bug #1103537; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1103537; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5379
NOTE: https://github.com/HDFGroup/hdf5/pull/5722
NOTE: https://github.com/HDFGroup/hdf5/commit/804f3bace997e416917b235dbd3beac3652a8a05
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-2913 (A vulnerability was found in HDF5 up to 1.14.6. It has been rated as c ...)
- - hdf5 <unfixed> (bug #1103538; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1103538; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5376
NOTE: https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
CVE-2025-2912 (A vulnerability was found in HDF5 up to 1.14.6. It has been declared a ...)
- - hdf5 <unfixed> (bug #1103539; unimportant)
+ - hdf5 2.1.0+repack-1 (bug #1103539; unimportant)
NOTE: https://github.com/HDFGroup/hdf5/issues/5370
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/7cc8b5e1010a09c892bc97ac32d9515c3777ce07 (2.0.0)
NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b5c1c7eb220043b8a0eaaa02bb7bb912302eca87
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b5c1c7eb220043b8a0eaaa02bb7bb912302eca87
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/0bf74c80/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list