PT-2026-68345 · Hdf5 · Hdf5

CVE-2026-19023

·

Published

2026-08-05

·

Updated

2026-08-06

CVSS v4.0

6.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HDF5 versions prior to 2.3.0
Description An untrusted pointer dereference exists in the render bin output() function of the h5dump tool. This occurs when a variable-length string dataset containing more than one element is dumped in binary mode. The issue corrupts the per-element stride calculation, leading subsequent elements to be read from a misaligned offset and dereferenced as a pointer, which can result in a denial of service.
Recommendations Update HDF5 to version 2.3.0 or later. As a temporary workaround, avoid using the render bin output() function to dump variable-length string datasets in binary mode.

Exploit

Fix

DoS

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94493
CVE-2026-19023
ECHO-664C-66C9-A47C

Affected Products

Hdf5