The following vulnerability was published for hdf5.
CVE-2025-2923[0]:
| A vulnerability, which was classified as problematic, has been found
| in HDF5 up to 1.14.6. Affected by this issue is the function
| H5F_addr_encode_len of the file src/H5Fint.c. The manipulation of
| the argument pp leads to heap-based buffer overflow. Attacking
| locally is a requirement. The exploit has been disclosed to the
| public and may be used.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.