PT-2026-68346 · Hdf5 · Hdf5
CVE-2026-19024
·
Published
2026-08-05
·
Updated
2026-08-06
CVSS v4.0
8.2
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
HDF5 versions prior to 2.3.0
Description
A NULL pointer dereference occurs in the
H5Pget fill value() function. This happens when a dataset contains a version 1 or 2 fill value message where the "defined" flag is set and the size field is negative. Because this value is not normalized to the library's "undefined" sentinel, it reaches H5T path find() with a NULL datatype, allowing an attacker to cause a denial of service.Recommendations
Update HDF5 to version 2.3.0 or later.
Exploit
Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hdf5