CVE-2026-26199
5.9
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If H5Iget_name is invoked on a group id with 0 for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if H5Iget_name is invoked in a way where size can be forced to zero, and there is important data before the name buffer.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HDFGroup | hdf5 | <= 1.14.6 | affected |
Weaknesses
- CWE-124: CWE-124: Buffer Underwrite ('Buffer Underflow')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
- https://github.com/HDFGroup/hdf5/blob/develop/src/H5Gname.c#L474
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.