Out-of-bounds Write Vulnerability in Unidata NetCDF Product
CVE-2026-86095

8.5HIGH

Key Information:

Vendor

Unidata

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-86095?

An out-of-bounds write vulnerability exists in Unidata's netcdf-c up to version 4.10.1, specifically within the NC4_HDF5_inq_attname() function. This flaw allows for the copying of oversized HDF5 attribute names into a fixed 256-byte buffer without appropriate length validation. Consequently, attackers can exploit this vulnerability by creating HDF5 files containing excessively long attribute names, leading to potential memory corruption and application crashes during the enumeration of these attribute names.

Affected Version(s)

netcdf-c 0 <= 4.10.1

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Holmquist
.