NULL Pointer Dereference Vulnerability in HDF5 by The HDF Group
CVE-2026-17574

5.2MEDIUM

Key Information:

Status
Vendor
CVE Published:
27 July 2026

What is CVE-2026-17574?

The HDF5 library experiences a NULL pointer dereference vulnerability caused by processing a specially crafted HDF5 file. This occurs when an attribute is read, which contains an invalid variable-length datatype type field. When this situation arises, the application may unexpectedly crash, posing a risk during data handling processes.

Affected Version(s)

HDF5 <= 2.1.1

References

CVSS V4

Score:
5.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.