[Git][security-tracker-team/security-tracker][master] Update status for some hdf5 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 6 06:40:23 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b5c1c7eb by Salvatore Bonaccorso at 2026-08-06T07:40:07+02:00
Update status for some hdf5 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7612,7 +7612,7 @@ CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability. Processi
 	[bullseye] - hdf5 <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc (2.2.0-rc1)
 CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library. Proces ...)
-	- hdf5 <unfixed> (bug #1143000)
+	- hdf5 2.1.0+repack-1 (bug #1143000)
 	[bookworm] - hdf5 <postponed> (Minor issue)
 	[bullseye] - hdf5 <postponed> (Minor issue)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/6124
@@ -15349,7 +15349,7 @@ CVE-2026-26199 (HDF5 is a high-performance library and a file format specificati
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
 	TODO: isolate fixing commit
 CVE-2026-26197 (HDF5 is a high-performance library and a file format specification tha ...)
-	- hdf5 <unfixed> (bug #1143002)
+	- hdf5 2.1.0+repack-1 (bug #1143002)
 	[bookworm] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
 	[bullseye] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f
@@ -196437,10 +196437,10 @@ CVE-2025-7069 (A vulnerability, which was classified as problematic, was found i
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5550
 	NOTE: Negligible security impact
 CVE-2025-7068 (A vulnerability, which was classified as problematic, has been found i ...)
-	- hdf5 <unfixed> (bug #1108885; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1108885; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5578
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5817
-	NOTE: https://github.com/HDFGroup/hdf5/commit/7dd110251d67b2c8cfe48d2e7a0b21a2e0c06432
+	NOTE: https://github.com/HDFGroup/hdf5/commit/7dd110251d67b2c8cfe48d2e7a0b21a2e0c06432 (2.0.0)
 	NOTE: Negligible security impact
 CVE-2025-53605 (The protobuf crate before 3.7.2 for Rust allows uncontrolled recursion ...)
 	- rust-protobuf 3.7.2-1 (bug #1103833)
@@ -196511,10 +196511,10 @@ CVE-2025-1735 (In PHP versions:8.1.* before 8.1.33, 8.2.* before 8.2.29, 8.3.* b
 	NOTE: https://github.com/php/php-src/security/advisories/GHSA-hrwm-9436-5mv3
 	NOTE: Fixed by: https://github.com/php/php-src/commit/9376aeef9f8ff81f2705b8016237ec3e30bdee44 (php-8.1.33)
 CVE-2025-7067 (A vulnerability classified as problematic was found in HDF5 1.14.6. Th ...)
-	- hdf5 <unfixed> (bug #1108886; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1108886; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5577
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5815
-	NOTE: https://github.com/HDFGroup/hdf5/commit/ea4b483d981b1c73ba2b8185c544565e4b05ae0e
+	NOTE: https://github.com/HDFGroup/hdf5/commit/ea4b483d981b1c73ba2b8185c544565e4b05ae0e (2.0.0)
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-7066 (Jirafeau normally prevents browser preview for text files due to the p ...)
 	NOT-FOR-US: Jirafeau
@@ -198314,10 +198314,10 @@ CVE-2025-6857 (A vulnerability has been found in HDF5 1.14.6 and classified as p
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5575
 	NOTE: Negligible security impact
 CVE-2025-6856 (A vulnerability, which was classified as problematic, was found in HDF ...)
-	- hdf5 <unfixed> (unimportant)
+	- hdf5 2.1.0+repack-1 (unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5574
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5829
-	NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675
+	NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675 (2.0.0)
 	NOTE: Negligible security impact
 CVE-2025-6855 (A vulnerability, which was classified as critical, has been found in c ...)
 	NOT-FOR-US: Langchain-Chatchat
@@ -198419,10 +198419,10 @@ CVE-2025-53391 (The Debian zuluPolkit/CMakeLists.txt file for zuluCrypt through
 	- zulucrypt <removed> (bug #1108288)
 	[bullseye] - zulucrypt <end-of-life> (EOL in bullseye LTS)
 CVE-2025-6816 (A vulnerability classified as problematic was found in HDF5 1.14.6. Th ...)
-	- hdf5 <unfixed> (bug #1108482; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1108482; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5571
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5829
-	NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675
+	NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675 (2.0.0)
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-6778 (A vulnerability, which was classified as problematic, was found in cod ...)
 	NOT-FOR-US: code-projects
@@ -198861,10 +198861,10 @@ CVE-2025-6752 (A vulnerability has been found in Linksys WRT1900ACS, EA7200, EA7
 CVE-2025-6751 (A vulnerability, which was classified as critical, was found in Linksy ...)
 	NOT-FOR-US: Linksys
 CVE-2025-6750 (A vulnerability, which was classified as problematic, has been found i ...)
-	- hdf5 <unfixed> (bug #1108409; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1108409; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5549
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5856
-	NOTE: https://github.com/HDFGroup/hdf5/commit/86149a098837a37b2513746e9baf84010f75fb54
+	NOTE: https://github.com/HDFGroup/hdf5/commit/86149a098837a37b2513746e9baf84010f75fb54 (2.0.0)
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-6749 (A vulnerability classified as critical was found in huija bicycleShari ...)
 	NOT-FOR-US: bicycleSharingServer
@@ -199896,10 +199896,10 @@ CVE-2025-6518 (A vulnerability was found in PySpur-Dev pyspur up to 0.1.18. It h
 CVE-2025-6517 (A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified ...)
 	NOT-FOR-US: Dromara MaxKey
 CVE-2025-6516 (A vulnerability has been found in HDF5 up to 1.14.6 and classified as  ...)
-	- hdf5 <unfixed> (unimportant)
+	- hdf5 2.1.0+repack-1 (unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5581
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5756
-	NOTE: https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70
+	NOTE: https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70 (2.0.0)
 	NOTE: Negligible security impact
 CVE-2025-6513 (Standard Windows users can access the configuration file for database  ...)
 	NOT-FOR-US: Bizerba
@@ -200746,9 +200746,9 @@ CVE-2025-6270 (A vulnerability, which was classified as critical, has been found
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5580
 	NOTE: Negligible security impact
 CVE-2025-6269 (A vulnerability classified as critical was found in HDF5 up to 1.14.6. ...)
-	- hdf5 <unfixed> (bug #1108155; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1108155; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5579
-	NOTE: https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70
+	NOTE: https://github.com/HDFGroup/hdf5/commit/3914bb7f7ec7105d8bfbeb3aebd92e867cff5b70 (2.0.0)
 	NOTE: Negligible security impact
 CVE-2025-6268 (A vulnerability classified as problematic has been found in Luna Imagi ...)
 	NOT-FOR-US: Luna Imaging
@@ -228560,28 +228560,28 @@ CVE-2025-30211 (Erlang/OTP is a set of libraries for the Erlang programming lang
 	NOTE: https://github.com/erlang/otp/commit/d64d9fb0688092356a336e38a8717499113312a0 (OTP-25.3.2.19, OTP-26.2.5.10, OTP-27.3.1)
 	NOTE: https://github.com/erlang/otp/commit/5ee26eb412a76ba1c6afdf4524b62939a48d1bce (OTP-25.3.2.19, OTP-26.2.5.10, OTP-27.3.1)
 CVE-2025-2926 (A vulnerability was found in HDF5 up to 1.14.6 and classified as probl ...)
-	- hdf5 <unfixed> (bug #1103531; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1103531; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5384
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5841
-	NOTE: https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2
+	NOTE: https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2 (2.0.0)
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-2925 (A vulnerability has been found in HDF5 up to 1.14.6 and classified as  ...)
-	- hdf5 <unfixed> (bug #1103532; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1103532; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5383
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5739
-	NOTE: https://github.com/HDFGroup/hdf5/commit/4310c19608455c17a213383d07715efb2918defc
+	NOTE: https://github.com/HDFGroup/hdf5/commit/4310c19608455c17a213383d07715efb2918defc (2.0.0)
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-2924 (A vulnerability, which was classified as problematic, was found in HDF ...)
-	- hdf5 <unfixed> (bug #1103533; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1103533; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5382
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5814
-	NOTE: https://github.com/HDFGroup/hdf5/commit/0a57195ca67d278f1cf7d01566c121048e337a59
+	NOTE: https://github.com/HDFGroup/hdf5/commit/0a57195ca67d278f1cf7d01566c121048e337a59 (2.0.0)
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-2923 (A vulnerability, which was classified as problematic, has been found i ...)
-	- hdf5 <unfixed> (bug #1103534; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1103534; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5381
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5829
-	NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675
+	NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675 (2.0.0)
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-2922 (A vulnerability classified as problematic was found in Netis WF-2404 1 ...)
 	NOT-FOR-US: Netis
@@ -228596,23 +228596,23 @@ CVE-2025-2917 (A vulnerability, which was classified as problematic, was found i
 CVE-2025-2916 (A vulnerability, which was classified as critical, has been found in A ...)
 	NOT-FOR-US: Aishida Call Center System
 CVE-2025-2915 (A vulnerability classified as problematic was found in HDF5 up to 1.14 ...)
-	- hdf5 <unfixed> (bug #1103536; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1103536; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5380
 	NOTE: https://github.com/HDFGroup/hdf5/commit/26a76bafdef3a0950d348a08667de161a19b7c2c
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-2914 (A vulnerability classified as problematic has been found in HDF5 up to ...)
-	- hdf5 <unfixed> (bug #1103537; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1103537; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5379
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5722
 	NOTE: https://github.com/HDFGroup/hdf5/commit/804f3bace997e416917b235dbd3beac3652a8a05
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-2913 (A vulnerability was found in HDF5 up to 1.14.6. It has been rated as c ...)
-	- hdf5 <unfixed> (bug #1103538; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1103538; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5376
 	NOTE: https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
 CVE-2025-2912 (A vulnerability was found in HDF5 up to 1.14.6. It has been declared a ...)
-	- hdf5 <unfixed> (bug #1103539; unimportant)
+	- hdf5 2.1.0+repack-1 (bug #1103539; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5370
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/7cc8b5e1010a09c892bc97ac32d9515c3777ce07 (2.0.0)
 	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b5c1c7eb220043b8a0eaaa02bb7bb912302eca87

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b5c1c7eb220043b8a0eaaa02bb7bb912302eca87
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/0bf74c80/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list