Heap-Based Buffer Overflow in HDF5 Software from HDF Group
CVE-2026-17572

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-17572?

A heap-based buffer overflow vulnerability in the deserialization code of the SOHM list-index in HDF5 permits attackers to exploit this flaw by supplying a specially crafted HDF5 file. This file can be designed to declare a num_messages count that exceeds the list_max, resulting in out-of-bounds heap reads and writes during the execution of the H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum functions. Consequently, this can lead to a denial of service through system crashes, posing significant risks to any systems utilizing affected versions of HDF5.

Affected Version(s)

HDF5 <= 2.1.1

References

CVSS V4

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.