๐Ÿ” CVE Alert

CVE-2026-106547

UNKNOWN 0.0

HDF5 heap buffer overflow in H5VM_array_fill via crafted fill-value metadata

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks are read, H5D__fill_init() fills the fill-value buffer from datatype and dataspace metadata in the file. If that metadata is inconsistent with the buffer's allocated size, the write goes past the end of the buffer. The attacker can control the content written through the fill value stored in the file.

CWE CWE-122
Vendor the hdf group
Product hdf5
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for the hdf group hdf5

Be the first to know when new unknown vulnerabilities affecting the hdf group hdf5 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

The HDF Group / HDF5
1.10.0 < 2.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/HDFGroup/hdf5/pull/6529

Credits

๐Ÿ” 0xkylm