CVE-2026-17572

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.
References
Link Resource
https://github.com/HDFGroup/hdf5/issues/6501 Issue Tracking
Configurations

Configuration 1 (hide)

cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-27 16:17

Updated : 2026-08-18 18:56


NVD link : CVE-2026-17572

Mitre link : CVE-2026-17572

CVE.ORG link : CVE-2026-17572


JSON object : View

Products Affected

hdfgroup

  • hdf5
CWE
CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write