CVE-2026-17573

Summary

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.

Affected Software

VendorProductVersion RangeStatus
The HDF GroupHDF5<= 2.1.1affected

Weaknesses

  • CWE-415: CWE-415 Double free

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References