PT-2026-68345 · Hdf5 · Hdf5
CVE-2026-19023
·
Published
2026-08-05
·
Updated
2026-08-06
CVSS v4.0
6.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
HDF5 versions prior to 2.3.0
Description
An untrusted pointer dereference exists in the
render bin output() function of the h5dump tool. This occurs when a variable-length string dataset containing more than one element is dumped in binary mode. The issue corrupts the per-element stride calculation, leading subsequent elements to be read from a misaligned offset and dereferenced as a pointer, which can result in a denial of service.Recommendations
Update HDF5 to version 2.3.0 or later.
As a temporary workaround, avoid using the
render bin output() function to dump variable-length string datasets in binary mode.Exploit
Fix
DoS
Untrusted Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hdf5