{
  "threat_severity" : "Moderate",
  "public_date" : "2024-05-10T00:00:00Z",
  "bugzilla" : {
    "description" : "hdf5: multiple CVEs",
    "id" : "2280037",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2280037"
  },
  "details" : [ "HDF5 through 1.13.3 and/or 1.14.2 contains a stack buffer overflow in H5HG_read, resulting in denial of service or potential code execution." ],
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux AI 1.5 for RHEL 9.4",
    "release_date" : "2025-04-10T00:00:00Z",
    "advisory" : "RHSA-2025:3801",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
    "package" : "hdf5-0:1.14.6-3.1.el9ai"
  }, {
    "product_name" : "Red Hat Enterprise Linux AI 1.5 for RHEL 9.4",
    "release_date" : "2025-04-10T00:00:00Z",
    "advisory" : "RHSA-2025:3801",
    "cpe" : "cpe:/a:redhat:enterprise_linux_ai:1.5::el9",
    "package" : "libaec-0:1.1.3-1.el9ai"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat OpenStack Platform 16.1",
    "fix_state" : "Out of support scope",
    "package_name" : "hdf5",
    "cpe" : "cpe:/a:redhat:openstack:16.1"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-29162\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-29162\nhttps://www.hdfgroup.org/2024/05/new-hdf5-cve-issues-fixed-in-1-14-4/" ],
  "name" : "CVE-2024-29162",
  "csaw" : false
}