PT-2026-93831 · Hdf5 · Hdf5

·

CVE-2026-92627

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions HDF5 versions prior to 1.14.2
Description A heap-use-after-free issue exists in the H5T conv f f() function within src/H5Tconv.c. This occurs during the conversion of a compound datatype containing floating-point members during a dataset read, where a temporary buffer allocated with calloc() is freed and then accessed again within the same routine. A remote attacker can trigger this by providing a crafted HDF5 file with a specially constructed compound datatype to an application that reads the dataset, such as h5dump. This may lead to a crash or memory corruption, potentially allowing remote code execution.
Recommendations Update to version 1.14.2 or later.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92627
ECHO-8D08-566A-3802

Affected Products

Hdf5