Heap-based Buffer Over-read in HDF5 Software by HDF Group
CVE-2026-19029

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-19029?

A heap-based buffer over-read vulnerability in the HDF5 software allows attackers to exploit crafted HDF5 files. This issue arises in the H5Z__filter_scaleoffset() function, where the decoder improperly handles the 'minimum bits' variable leading to the risk of denial of service via application crashes. The flaw occurs when the system does not verify that the chunk contains the expected number of bytes during the decoding of data, potentially controlled through malicious scale-offset filter parameters.

Affected Version(s)

HDF5 < 2.2.0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mtholmquist
.