PT-2026-39358 · Julia · Hdf5 Jll

Published

2026-04-29

·

Updated

2026-04-29

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
HDF5 Library through 1.14.3 contains a heap-based buffer over-read caused by the unsafe use of strdup in H5MM xstrdup in H5MM.c (called from H5G ent to link in H5Glink.c).

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-312

Affected Products

Hdf5 Jll