CVE-2026-17572
HDF5 SOHM List Index Heap Buffer Overflow
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.
| CWE | CWE-125 CWE-787 |
| Vendor | the hdf group |
| Product | hdf5 |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for the hdf group hdf5
Be the first to know when new unknown vulnerabilities affecting the hdf group hdf5 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
The HDF Group / HDF5
<= 2.1.1