#1123961 netcdf-parallel: CVE-2025-14932 CVE-2025-14933 CVE-2025-14934 CVE-2025-14935 CVE-2025-14936

Package:
src:netcdf-parallel
Source:
src:netcdf-parallel
Submitter:
Salvatore Bonaccorso
Date:
2026-08-04 15:53:02 UTC
Severity:
normal
Tags:
#1123961#5
Date:
2025-12-25 06:43:42 UTC
From:
To:
Hi,

The following vulnerabilities were published for netcdf.

The set of reports oginate from ZDI reports and it not very clear if
the issues will get fixed and have not found public upstream
references where they track those. So this might be a first step at
all to track these properly as well for us downstream. For now the CVE
entries just refernce to the published ZDI reports.

CVE-2025-14932[0]:
| NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote
| Code Execution Vulnerability. This vulnerability allows remote
| attackers to execute arbitrary code on affected installations of NSF
| Unidata NetCDF-C. User interaction is required to exploit this
| vulnerability in that the target must visit a malicious page or open
| a malicious file.  The specific flaw exists within the parsing of
| time units. The issue results from the lack of proper validation of
| the length of user-supplied data prior to copying it to a fixed-
| length stack-based buffer. An attacker can leverage this
| vulnerability to execute code in the context of the current user.
| Was ZDI-CAN-27273.


CVE-2025-14933[1]:
| NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code
| Execution Vulnerability. This vulnerability allows remote attackers
| to execute arbitrary code on affected installations of NSF Unidata
| NetCDF-C. User interaction is required to exploit this vulnerability
| in that the target must visit a malicious page or open a malicious
| file.  The specific flaw exists within the parsing of NC variables.
| The issue results from the lack of proper validation of user-
| supplied data, which can result in an integer overflow before
| allocating a buffer. An attacker can leverage this vulnerability to
| execute code in the context of the current user. Was ZDI-CAN-27266.


CVE-2025-14934[2]:
| NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow
| Remote Code Execution Vulnerability. This vulnerability allows
| remote attackers to execute arbitrary code on affected installations
| of NSF Unidata NetCDF-C. User interaction is required to exploit
| this vulnerability in that the target must visit a malicious page or
| open a malicious file.  The specific flaw exists within the parsing
| of variable names. The issue results from the lack of proper
| validation of the length of user-supplied data prior to copying it
| to a fixed-length stack-based buffer. An attacker can leverage this
| vulnerability to execute code in the context of the current user.
| Was ZDI-CAN-27267.


CVE-2025-14935[3]:
| NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow
| Remote Code Execution Vulnerability. This vulnerability allows
| remote attackers to execute arbitrary code on affected installations
| of NSF Unidata NetCDF-C. User interaction is required to exploit
| this vulnerability in that the target must visit a malicious page or
| open a malicious file.  The specific flaw exists within the parsing
| of dimension names. The issue results from the lack of proper
| validation of the length of user-supplied data prior to copying it
| to a fixed-length heap-based buffer. An attacker can leverage this
| vulnerability to execute code in the context of the current user.
| Was ZDI-CAN-27168.


CVE-2025-14936[4]:
| NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow
| Remote Code Execution Vulnerability. This vulnerability allows
| remote attackers to execute arbitrary code on affected installations
| of NSF Unidata NetCDF-C. User interaction is required to exploit
| this vulnerability in that the target must visit a malicious page or
| open a malicious file.  The specific flaw exists within the parsing
| of attribute names. The issue results from the lack of proper
| validation of the length of user-supplied data prior to copying it
| to a fixed-length stack-based buffer. An attacker can leverage this
| vulnerability to execute code in the context of the current user.
| Was ZDI-CAN-27269.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-14932
https://www.cve.org/CVERecord?id=CVE-2025-14932
[1] https://security-tracker.debian.org/tracker/CVE-2025-14933
https://www.cve.org/CVERecord?id=CVE-2025-14933
[2] https://security-tracker.debian.org/tracker/CVE-2025-14934
https://www.cve.org/CVERecord?id=CVE-2025-14934
[3] https://security-tracker.debian.org/tracker/CVE-2025-14935
https://www.cve.org/CVERecord?id=CVE-2025-14935
[4] https://security-tracker.debian.org/tracker/CVE-2025-14936
https://www.cve.org/CVERecord?id=CVE-2025-14936

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1123961#20
Date:
2026-08-04 15:51:38 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
netcdf-parallel, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1123961@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Alastair McKinstry <mckinstry@debian.org> (supplier of updated netcdf-parallel package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 02 Aug 2026 13:52:47 +0100
Source: netcdf-parallel
Architecture: source
Version: 1:4.10.1-1
Distribution: unstable
Urgency: medium
Maintainer: Alastair McKinstry <mckinstry@debian.org>
Changed-By: Alastair McKinstry <mckinstry@debian.org>
Closes: 977545 1003943 1036168 1123961
Changes:
 netcdf-parallel (1:4.10.1-1) unstable; urgency=medium
 .
   * New upstream release. Closes: #1123961
     Refresh patches
     Fixes: CVE-2025-14932, CVE-2025-14933, CVE-2025-14934,
            CVE-2025-14935, CVE-2025-14936
   * Update d/copyright
   * Update symbols files
   * Fix include path in pkgconfig files. Closes: #1036168, #977545, #1003943
   * d/rules: Ensure repeat builds works
Checksums-Sha1:
 0f99c7cce014952f439846ea92914c7592479530 2637 netcdf-parallel_4.10.1-1.dsc
 fb5b487f66ae12d81979c6fb558ef6deb7034633 25714348 netcdf-parallel_4.10.1.orig.tar.gz
 f5915a5989ee9fee42ad22db6ab9e671539bfefd 54756 netcdf-parallel_4.10.1-1.debian.tar.xz
 d85c8fcf867751a66827c54519e4441b786fb9f9 13947 netcdf-parallel_4.10.1-1_arm64.buildinfo
Checksums-Sha256:
 5dc8e3ad3808261dba7a76e2319f5867e893c596d4074e33da559964c66f951e 2637 netcdf-parallel_4.10.1-1.dsc
 33c27231c478c3b35da7c7758fbdd02da1fe407abcb16ddfe195f69d164f930d 25714348 netcdf-parallel_4.10.1.orig.tar.gz
 a34745b6eb5675b96481ce44c37180c04b672ebe35d66c405e4fb332de0003a9 54756 netcdf-parallel_4.10.1-1.debian.tar.xz
 c0443a580c291d5db09121fea8595b7e41cadf9d6cd305dbfd9c612dcffe17d3 13947 netcdf-parallel_4.10.1-1_arm64.buildinfo
Files:
 bcfca3a1febce62b2fb9cc26899fd0a4 2637 science optional netcdf-parallel_4.10.1-1.dsc
 9d56028b4032c67cd63b3cc5ae3e6b5f 25714348 science optional netcdf-parallel_4.10.1.orig.tar.gz
 ebe18278fd69c93a0d8b988a6ede4507 54756 science optional netcdf-parallel_4.10.1-1.debian.tar.xz
 a5566a083551f839e520ffb084e03118 13947 science optional netcdf-parallel_4.10.1-1_arm64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEgjg86RZbNHx4cIGiy+a7Tl2a06UFAmpyA7oACgkQy+a7Tl2a
06VS2w/+IMxRnAun0ccjtmKIba7AaieiTCb648gcB6SyULpBuAhyLYVh29P7+ife
eBTs8JyXV2gMAPV5370uIKxKt4nu/Bx73SaiFlUc6zZVgLshbRsMdt5PWkuf/oN4
h+gq+I/UGVv1yt6Clm7XqwP6Pgy2fRFTw7A0cG7aDH/Dk1MiSgyw4/lhB5KzUcki
FkwM2lHQxPw/uAbkTy7CsuW0iM1e6Z/61gq5StxLcMqRyeK58+C3c/bqEpy4B+IK
hmUOAAC8xPY0GSEAif/vXxmvBYpiTs5GwdpGvLtmAxQJ1JA0EoT6Gljwfxo6z/6q
gudGRiDF3KdJ+c1tFPxonJFfCzhVvgH6RHszoPwohhBucUgJOM/3p9WXMj07TRAe
6itzgTTIlrFHQb982JDL8XIN2+G09XD5pu2ZjqyUzXv1kS0IHd56756O2kLKjYHa
cBLkELUlnV9RQtHOSpB3R62R7gxiLbZDa/uEvwx3f/eOgrzcyrECe5tglg/rkVDv
jCv2p5tltZqOsYCUvBmaDfl1uffpUziM5gUuek7dxXn1G9FPgt4kqA+1S34Qkd8S
LVMO2oxjtTl1D1SMLvCpNgUBa0JG23LfunWNKrXp8gAYRd3T7F9ZgOw8PJ+bWJbl
wsnsGPwKbjFpoG2XCBwiupNzLrGW0UamvX4ZcYfRZtdVEv1tItU=
=/RUZ
-----END PGP SIGNATURE-----