CVE-2024-32624 HDF5 Library through 1.14.3 contains a heap-based buffer overflow in H5T__ref_mem_setnull in H5Tref.c (called from H5T__conv_ref in H5Tconv.c) resulting in the corruption of the instruction pointer.
Information published.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
