CVE-2020-18232 (https://github.com/winson2004aa/PAAFS/tree/master/vul2): Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file. CVE-2020-18494 (https://github.com/magicSwordsMan/PAAFS/tree/master/vul12): Buffer Overflow vulnerability in function H5S_close in H5S.c in HDF5 1.10.4 allows remote attackers to run arbitrary code via creation of crafted file. No links to reports upstream, wouldn't be surprised if these are complete bogus.
Where are the fixes?