CVE-2026-17572
EUVD-2026-4931827.07.2026, 16:17
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hdfgroup | hdf5 | 𝑥 < 2.2.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration