Heap-Based Buffer Overflow in HDF5 Affects Remote Applications
CVE-2026-106547

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-106547?

A heap-based buffer overflow flaw in HDF5 can be exploited by an attacker who crafts a malicious HDF5 file. This vulnerability arises within the H5VM_array_fill() function in src/H5VM.c, where improper handling of dataset metadata leads to a potential application crash or execution of arbitrary code. Specifically, if the metadata for datatype and dataspace is inconsistent with the allocated buffer size, the function may write beyond the buffer's boundaries, allowing an attacker to control the fill value stored in the file and manipulate application behavior.

Affected Version(s)

HDF5 1.10.0 < 2.2.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xkylm
.