[Git][security-tracker-team/security-tracker][master] Update status for hdf5 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 6 06:47:25 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8f2daced by Salvatore Bonaccorso at 2026-08-06T07:46:40+02:00
Update status for hdf5 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7607,24 +7607,27 @@ CVE-2026-24252 (NVIDIA NeMo for Linux contains a vulnerability where an attacker
 CVE-2026-17612 (Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to a ...)
 	NOT-FOR-US: Honeywell
 CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability. Processing a c ...)
-	- hdf5 <unfixed> (bug #1143001)
+	- hdf5 <unfixed> (bug #1143001; unimportant)
 	[bookworm] - hdf5 <postponed> (Minor issue)
 	[bullseye] - hdf5 <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc (2.2.0-rc1)
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library. Proces ...)
-	- hdf5 2.1.0+repack-1 (bug #1143000)
+	- hdf5 2.1.0+repack-1 (bug #1143000; unimportant)
 	[bookworm] - hdf5 <postponed> (Minor issue)
 	[bullseye] - hdf5 <postponed> (Minor issue)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/6124
 	NOTE: https://github.com/HDFGroup/hdf5/pull/6160
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/dd3080a58cc6bb86f3b34284399915da9e513262 (2.1.0)
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-17572 (Heap-based buffer overflow in the SOHM list-index deserialization code ...)
-	- hdf5 <unfixed> (bug #1142999)
+	- hdf5 <unfixed> (bug #1142999; unimportant)
 	[bookworm] - hdf5 <postponed> (Minor issue)
 	[bullseye] - hdf5 <postponed> (Minor issue)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/6501
 	NOTE: https://github.com/HDFGroup/hdf5/pull/6499
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/20f0b9564bc46154e60f8d35578720a599d41552 (2.2.0-rc1)
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-17570 (Improper access control in the PAM password history endpoints in Devol ...)
 	NOT-FOR-US: Devolutions
 CVE-2026-17569 (Improper access control in the NetBox synchronizer in Devolutions Serv ...)
@@ -15342,18 +15345,14 @@ CVE-2026-27823 (A vulnerability has been identified in EGroupware that may lead
 CVE-2026-26483 (Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scrip ...)
 	NOT-FOR-US: Mettle SendPortal
 CVE-2026-26199 (HDF5 is a high-performance library and a file format specification tha ...)
-	- hdf5 <unfixed> (bug #1143003)
-	[trixie] - hdf5 <no-dsa> (Minor issue)
-	[bookworm] - hdf5 <postponed> (Minor issue; H5G_get_name buffer underflow only when caller passes size=0 to H5Iget_name)
-	[bullseye] - hdf5 <postponed> (Minor issue; H5G_get_name buffer underflow only when caller passes size=0 to H5Iget_name)
+	- hdf5 <unfixed> (bug #1143003; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
-	TODO: isolate fixing commit
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-26197 (HDF5 is a high-performance library and a file format specification tha ...)
-	- hdf5 2.1.0+repack-1 (bug #1143002)
-	[bookworm] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
-	[bullseye] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
+	- hdf5 2.1.0+repack-1 (bug #1143002; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/8cd9f7a7ba6757fbb72e36bbe23e127f8507c8a6 (2.1.0)
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-25039 (Parsec is a cloud-based application for simple and cryptographically s ...)
 	NOT-FOR-US: Parsec
 CVE-2026-21824 (HCL Commerce contains an privilege escalation vulnerability that could ...)
@@ -85661,7 +85660,7 @@ CVE-2026-29861 (PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL
 CVE-2026-29043 (HDF5 is software for managing data. In 1.14.1-2 and earlier, an attack ...)
 	- hdf5 <unfixed> (unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-qm2m-5g5w-2277
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-29002 (CouchCMS contains a privilege escalation vulnerability that allows aut ...)
 	NOT-FOR-US: CouchCMS
 CVE-2026-23782 (An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An ...)
@@ -86081,7 +86080,7 @@ CVE-2026-35063 (OpenPLC_V3 REST API endpoint checks for JWT presence but never v
 CVE-2026-34734 (HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-us ...)
 	- hdf5 <unfixed> (unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-w7v2-9cmr-pwwj
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-34512 (OpenClaw before 2026.3.25 contains an improper access control vulnerab ...)
 	NOT-FOR-US: OpenClaw
 CVE-2026-34500 (CLIENT_CERT authentication does not fail as expected for some scenario ...)
@@ -112216,7 +112215,7 @@ CVE-2026-26200 (HDF5 is software for managing data. Prior to version 1.14.4-2, a
 	- hdf5 <unfixed> (unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5p2m-j456-9mr2
 	NOTE: said to be fixed in 1.14.4-2 upstream
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-26193 (Open WebUI is a self-hosted artificial intelligence platform designed  ...)
 	NOT-FOR-US: Open WebUI
 CVE-2026-26192 (Open WebUI is a self-hosted artificial intelligence platform designed  ...)
@@ -196515,7 +196514,7 @@ CVE-2025-7067 (A vulnerability classified as problematic was found in HDF5 1.14.
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5577
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5815
 	NOTE: https://github.com/HDFGroup/hdf5/commit/ea4b483d981b1c73ba2b8185c544565e4b05ae0e (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-7066 (Jirafeau normally prevents browser preview for text files due to the p ...)
 	NOT-FOR-US: Jirafeau
 CVE-2025-7061 (A vulnerability was found in Intelbras InControl up to 2.21.60.9. It h ...)
@@ -198423,7 +198422,7 @@ CVE-2025-6816 (A vulnerability classified as problematic was found in HDF5 1.14.
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5571
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5829
 	NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675 (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-6778 (A vulnerability, which was classified as problematic, was found in cod ...)
 	NOT-FOR-US: code-projects
 CVE-2025-6777 (A vulnerability, which was classified as critical, has been found in c ...)
@@ -198865,7 +198864,7 @@ CVE-2025-6750 (A vulnerability, which was classified as problematic, has been fo
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5549
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5856
 	NOTE: https://github.com/HDFGroup/hdf5/commit/86149a098837a37b2513746e9baf84010f75fb54 (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-6749 (A vulnerability classified as critical was found in huija bicycleShari ...)
 	NOT-FOR-US: bicycleSharingServer
 CVE-2025-6748 (A vulnerability classified as problematic has been found in Bharti Air ...)
@@ -228564,25 +228563,25 @@ CVE-2025-2926 (A vulnerability was found in HDF5 up to 1.14.6 and classified as
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5384
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5841
 	NOTE: https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2 (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2925 (A vulnerability has been found in HDF5 up to 1.14.6 and classified as  ...)
 	- hdf5 2.1.0+repack-1 (bug #1103532; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5383
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5739
 	NOTE: https://github.com/HDFGroup/hdf5/commit/4310c19608455c17a213383d07715efb2918defc (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2924 (A vulnerability, which was classified as problematic, was found in HDF ...)
 	- hdf5 2.1.0+repack-1 (bug #1103533; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5382
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5814
 	NOTE: https://github.com/HDFGroup/hdf5/commit/0a57195ca67d278f1cf7d01566c121048e337a59 (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2923 (A vulnerability, which was classified as problematic, has been found i ...)
 	- hdf5 2.1.0+repack-1 (bug #1103534; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5381
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5829
 	NOTE: https://github.com/HDFGroup/hdf5/commit/29c847a43db0cdc85b01cafa5a7613ea73932675 (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2922 (A vulnerability classified as problematic was found in Netis WF-2404 1 ...)
 	NOT-FOR-US: Netis
 CVE-2025-2921 (A vulnerability classified as critical has been found in Netis WF-2404 ...)
@@ -228599,23 +228598,23 @@ CVE-2025-2915 (A vulnerability classified as problematic was found in HDF5 up to
 	- hdf5 2.1.0+repack-1 (bug #1103536; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5380
 	NOTE: https://github.com/HDFGroup/hdf5/commit/26a76bafdef3a0950d348a08667de161a19b7c2c
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2914 (A vulnerability classified as problematic has been found in HDF5 up to ...)
 	- hdf5 2.1.0+repack-1 (bug #1103537; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5379
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5722
 	NOTE: https://github.com/HDFGroup/hdf5/commit/804f3bace997e416917b235dbd3beac3652a8a05
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2913 (A vulnerability was found in HDF5 up to 1.14.6. It has been rated as c ...)
 	- hdf5 2.1.0+repack-1 (bug #1103538; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5376
 	NOTE: https://github.com/HDFGroup/hdf5/commit/d37b537ff256f0fa65cb4f82b20f286ad9a2e1e2
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2912 (A vulnerability was found in HDF5 up to 1.14.6. It has been declared a ...)
 	- hdf5 2.1.0+repack-1 (bug #1103539; unimportant)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5370
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/7cc8b5e1010a09c892bc97ac32d9515c3777ce07 (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2911 (Unauthorised access to the call forwarding service system in MeetMe pr ...)
 	NOT-FOR-US: MeetMe
 CVE-2025-2910 (User enumeration in the password reset module of the MeetMe authentica ...)
@@ -232943,15 +232942,15 @@ CVE-2025-2320 (A vulnerability has been found in 274056675 springboot-openai-cha
 CVE-2025-2310 (A vulnerability was found in HDF5 1.14.6 and classified as critical. T ...)
 	- hdf5 <unfixed> (bug #1103540; unimportant)
 	NOTE: https://github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc4.md
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2309 (A vulnerability has been found in HDF5 1.14.6 and classified as critic ...)
 	- hdf5 <unfixed> (bug #1103541; unimportant)
 	NOTE: https://github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc3.md
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2308 (A vulnerability, which was classified as critical, was found in HDF5 1 ...)
 	- hdf5 <unfixed> (bug #1103542; unimportant)
 	NOTE: https://github.com/madao123123/crash_report/blob/main/hdf5_poc/hdf5_poc2.md
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2295 (EDK2 contains a vulnerability in BIOS where a user may cause an Intege ...)
 	- edk2 2025.02-4 (bug #1100594)
 	[bookworm] - edk2 <no-dsa> (Minor issue)
@@ -234475,7 +234474,7 @@ CVE-2025-2153 (A vulnerability, which was classified as critical, was found in H
 	NOTE: https://github.com/HDFGroup/hdf5/issues/5329
 	NOTE: https://github.com/HDFGroup/hdf5/pull/5795
 	NOTE: https://github.com/HDFGroup/hdf5/commit/38954615fc079538aa45d48097625a6d76aceef0 (2.0.0)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2025-2152 (A vulnerability, which was classified as critical, has been found in O ...)
 	- assimp 6.0.2+ds-1 (bug #1100438)
 	[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
@@ -323244,23 +323243,23 @@ CVE-2024-34074 (Frappe is a full-stack web application framework. Prior to 15.26
 CVE-2024-33877 (HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5T__c ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-33876 (HDF5 Library through 1.14.3 has a heap buffer overflow in H5S__point_d ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-33875 (HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5O__l ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-33874 (HDF5 Library through 1.14.3 has a heap buffer overflow in H5O__mtime_n ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-33873 (HDF5 Library through 1.14.3 has a heap-based buffer overflow in H5D__s ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-33454 (Buffer Overflow vulnerability in esp-idf v.5.1 allows a remote attacke ...)
 	NOT-FOR-US: esp-idf
 CVE-2024-32874 (Frigate is a network video recorder (NVR) with realtime local object d ...)
@@ -323290,83 +323289,83 @@ CVE-2024-32655 (Npgsql is the .NET data provider for PostgreSQL. The `WriteBind(
 CVE-2024-32624 (HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32623 (HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32622 (HDF5 Library through 1.14.3 contains a out-of-bounds read operation in ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32621 (HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32620 (HDF5 Library through 1.14.3 contains a heap-based buffer over-read in  ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32619 (HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32618 (HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32617 (HDF5 Library through 1.14.3 contains a heap-based buffer over-read cau ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32616 (HDF5 Library through 1.14.3 contains a heap-based buffer over-read in  ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32615 (HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32614 (HDF5 Library through 1.14.3 has a SEGV in H5VM_memcpyvv in H5VM.c.)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32613 (HDF5 Library through 1.14.3 contains a heap-based buffer over-read in  ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32612 (HDF5 Library through 1.14.3 contains a heap-based buffer over-read in  ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32611 (HDF5 Library through 1.14.3 may use an uninitialized value in H5A__att ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32610 (HDF5 Library through 1.14.3 has a SEGV in H5T_close_real in H5T.c, res ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32609 (HDF5 Library through 1.14.3 allows stack consumption in the function H ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32608 (HDF5 library through 1.14.3 has memory corruption in H5A__close result ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32607 (HDF5 Library through 1.14.3 has a SEGV in H5A__close in H5Aint.c, resu ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32606 (HDF5 Library through 1.14.3 may attempt to dereference uninitialized v ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-32605 (HDF5 Library through 1.14.3 has a heap-based buffer over-read in H5VM_ ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-31954 (An issue was discovered in the installer in Samsung Portable SSD for T ...)
 	NOT-FOR-US: Samsung
 CVE-2024-31953 (An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it ...)
@@ -323388,43 +323387,43 @@ CVE-2024-29800 (Deserialization of Untrusted Data vulnerability in Timber Team &
 CVE-2024-29166 (HDF5 through 1.14.3 contains a buffer overflow in H5O__linfo_decode, r ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29165 (HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_fletcher ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29164 (HDF5 through 1.14.3 contains a stack buffer overflow in H5R__decode_he ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29163 (HDF5 through 1.14.3 contains a heap buffer overflow in H5T__bit_find,  ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29162 (HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in  ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29161 (HDF5 through 1.14.3 contains a heap buffer overflow in H5A__attr_relea ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29160 (HDF5 through 1.14.3 contains a heap buffer overflow in H5HG__cache_hea ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29159 (HDF5 through 1.14.3 contains a buffer overflow in H5Z__filter_scaleoff ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29158 (HDF5 through 1.14.3 contains a stack buffer overflow in H5FL_arr_mallo ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-29157 (HDF5 through 1.14.3 contains a heap buffer overflow in H5HG_read, resu ...)
 	- hdf5 1.14.5+repack-1 (bug #1070861; unimportant)
 	NOTE: https://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2024-28075 (The SolarWinds Access Rights Manager was susceptible to Remote Code Ex ...)
 	NOT-FOR-US: SolarWinds
 CVE-2024-24157 (Gnuboard g6 / https://github.com/gnuboard/g6 commit c2cc1f5069e00491ea ...)
@@ -488149,19 +488148,19 @@ CVE-2022-26061 (A heap-based buffer overflow vulnerability exists in the gif2h5
 	[buster] - hdf5 <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1487
 	NOTE: Starting with 1.10.10+repack-1 gif2h5 and h52gif are no longer installed
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2022-25972 (An out-of-bounds write vulnerability exists in the gif2h5 functionalit ...)
 	- hdf5 1.10.10+repack-1 (bug #1031726; unimportant)
 	[buster] - hdf5 <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1485
 	NOTE: Starting with 1.10.10+repack-1 gif2h5 and h52gif are no longer installed
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2022-25942 (An out-of-bounds read vulnerability exists in the gif2h5 functionality ...)
 	- hdf5 1.10.10+repack-1 (bug #1031726; unimportant)
 	[buster] - hdf5 <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1486
 	NOTE: Starting with 1.10.10+repack-1 gif2h5 and h52gif are no longer installed
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2022-0935 (Host Header injection in password Reset in GitHub repository livehelpe ...)
 	NOT-FOR-US: livehelperchat
 CVE-2022-26886
@@ -693034,7 +693033,7 @@ CVE-2019-8398 (An issue was discovered in the HDF HDF5 1.10.4 library. There is
 	[buster] - hdf5 <no-dsa> (Minor issue)
 	NOTE: https://github.com/magicSwordsMan/PAAFS/tree/master/vul6
 	NOTE: https://jira.hdfgroup.org/browse/HDFFV-10710
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2019-8397 (An issue was discovered in the HDF HDF5 1.10.4 library. There is an ou ...)
 	- hdf5 <unfixed> (unimportant)
 	[buster] - hdf5 <no-dsa> (Minor issue)
@@ -693050,7 +693049,7 @@ CVE-2019-8396 (A buffer overflow in H5O__layout_encode in H5Olayout.c in the HDF
 	NOTE: https://jira.hdfgroup.org/browse/HDFFV-10712
 	NOTE: HDFFV-10712 is marked to be closed in a future 1.10.8 upstream release.
 	NOTE: Upstream fix was made in May 2021 after the 1.12.0 release (Mar 2020)
-	NOTE: HDF not covered by security support, see https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1117722
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2019-8395 (An Insecure Direct Object Reference (IDOR) vulnerability exists in Zoh ...)
 	NOT-FOR-US: Zoho ManageEngine ServiceDesk Plus
 CVE-2019-8394 (Zoho ManageEngine ServiceDesk Plus (SDP) before 10.0 build 10012 allow ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8f2daceda5cba66e09639ddb1b3e9f62fe6e51b4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8f2daceda5cba66e09639ddb1b3e9f62fe6e51b4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/5ac5d01c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list