NULL Pointer Dereference Vulnerability in HDF5 by The HDF Group
CVE-2026-17574
5.2MEDIUM
What is CVE-2026-17574?
The HDF5 library experiences a NULL pointer dereference vulnerability caused by processing a specially crafted HDF5 file. This occurs when an attribute is read, which contains an invalid variable-length datatype type field. When this situation arises, the application may unexpectedly crash, posing a risk during data handling processes.
Affected Version(s)
HDF5 <= 2.1.1
