CVE Vulnerabilities

CVE-2021-46243

NULL Pointer Dereference

Published: Jan 21, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
6.2 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
NEGLIGIBLE
root.io logo minimus.io logo echo.ai logo

An untrusted pointer dereference vulnerability exists in HDF5 v1.13.1-1 via the function H5O__dtype_decode_helper () at hdf5/src/H5Odtype.c. This vulnerability can lead to a Denial of Service (DoS).

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Hdf5Hdfgroup1.13.1-1 (including)1.13.1-1 (including)
Hdf5Ubuntubionic*
Hdf5Ubuntufocal*
Hdf5Ubuntuimpish*
Hdf5Ubuntukinetic*
Hdf5Ubuntulunar*
Hdf5Ubuntumantic*
Hdf5Ubuntuoracular*
Hdf5Ubuntuplucky*
Hdf5Ubuntutrusty*
Hdf5Ubuntutrusty/esm*
Hdf5Ubuntuxenial*
Insighttoolkit4Ubuntubionic*
Insighttoolkit4Ubuntufocal*
Insighttoolkit4Ubuntuimpish*
Insighttoolkit4Ubuntukinetic*
Insighttoolkit4Ubuntulunar*
Insighttoolkit4Ubuntutrusty*
Insighttoolkit4Ubuntuxenial*
KisspliceUbuntubionic*
KisspliceUbuntufocal*
KisspliceUbuntuimpish*
KisspliceUbuntukinetic*
KisspliceUbuntulunar*
KisspliceUbuntumantic*
KisspliceUbuntuoracular*
KisspliceUbuntuplucky*
KisspliceUbuntutrusty*
KisspliceUbuntuxenial*
ParaviewUbuntubionic*
ParaviewUbuntufocal*
ParaviewUbuntuimpish*
ParaviewUbuntukinetic*
ParaviewUbuntulunar*
ParaviewUbuntumantic*
ParaviewUbuntuoracular*
ParaviewUbuntuplucky*
ParaviewUbuntutrusty*
ParaviewUbuntuxenial*
VtkUbuntutrusty*
VtkUbuntutrusty/esm*
VtkUbuntuxenial*
XdmfUbuntubionic*
XdmfUbuntufocal*
XdmfUbuntuimpish*
XdmfUbuntukinetic*
XdmfUbuntulunar*
XdmfUbuntumantic*
XdmfUbuntuoracular*
XdmfUbuntuplucky*
XdmfUbuntutrusty*
XdmfUbuntuxenial*

Potential Mitigations

References