Bug 1202622 - (CVE-2022-26061) VUL-0: CVE-2022-26061: hdf5: heap-based buffer overflow vulnerability in the gif2h5 functionality
(CVE-2022-26061)
VUL-0: CVE-2022-26061: hdf5: heap-based buffer overflow vulnerability in the ...
Status: RESOLVED UPSTREAM
Classification: Novell Products
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents
unspecified
Other Other
: P3 - Medium : Major
: ---
Assigned To: HPC Issue Tracker
Security Team bot
https://smash.suse.de/issue/340421/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-08-23 06:43 UTC by Alexander Bergmann
Modified: 2022-09-07 07:18 UTC (History)
4 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2022-08-23 06:43:30 UTC
CVE-2022-26061

A heap-based buffer overflow vulnerability exists in the gif2h5 functionality of
HDF5 Group libhdf5 1.10.4. A specially-crafted GIF file can lead to code
execution. An attacker can provide a malicious file to trigger this
vulnerability.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-26061
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26061
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1487
Comment 1 Alexander Bergmann 2022-08-23 07:10:21 UTC
From the version numbers all SUSE related packages seam to be clear.

SUSE:SLE-12-SP2:GA:Products:Update/hdf5  hdf5-1.10.8
SUSE:SLE-15:Update/hdf5                  hdf5-1.10.8
SUSE:SLE-15-SP1:Update/hdf5              hdf5-1.10.8
SUSE:SLE-15-SP2:Update/hdf5              hdf5-1.10.8
SUSE:SLE-15-SP3:Update/hdf5              hdf5-1.10.8
SUSE:SLE-15-SP4:GA/hdf5                  hdf5-1.10.8


There is no direct reference to a patch or git commit. We will leave the bug report open to check the correctness.
Comment 4 Gabriele Sonnu 2022-09-07 07:18:29 UTC
Not affected since we don't ship the GIF tools. Closing.