Double Free Vulnerability in HDF5 Library by HDF Group
CVE-2026-17573

4MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-17573?

A double free vulnerability exists in the HDF5 library due to mishandling of crafted HDF5 files with oversized chunk size fields. When processed through the h5repack utility, this flaw can lead to unintended memory management issues, potentially causing the application to abort. Users of the HDF5 library should exercise caution and apply any available patches to mitigate risks associated with this vulnerability.

Affected Version(s)

HDF5 Linux <= 2.1.1

References

CVSS V4

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.