it has been released on 2018-10-09, it fixes almost all CVEs of bug #661158 (stating the release note of 1.10.3) a simple bump from version 1.10.1 in portage works
In the meantime, 1.10.5 has been released.
The bug has been closed via the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=49aa89d2a6c9ebc6c939a985b271e30724e68815 commit 49aa89d2a6c9ebc6c939a985b271e30724e68815 Author: Benda Xu <heroxbd@gentoo.org> AuthorDate: 2019-03-31 03:24:21 +0000 Commit: Benda Xu <heroxbd@gentoo.org> CommitDate: 2019-03-31 03:24:21 +0000 sci-libs/hdf5: bump to 1.10.5 and EAPI 7. Suggested-By: Fabio Rossi, Bernd Bug: https://bugs.gentoo.org/661158 Closes: https://bugs.gentoo.org/674998 Package-Manager: Portage-2.3.52, Repoman-2.3.12 Signed-off-by: Benda Xu <heroxbd@gentoo.org> sci-libs/hdf5/Manifest | 1 + sci-libs/hdf5/hdf5-1.10.5.ebuild | 93 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 94 insertions(+)