CVE-2026-106547: fallo de gravedad alta en The HDF Group HDF5
HDF5 heap buffer overflow in H5VM_array_fill via crafted fill-value metadata
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.5epss 0.2%
probabilidad de explotación
0.2%top 95% de las CVE
explotación observada
noninguna fuente lo reporta
A heap-based buffer overflow in H5VM_array_fill() in src/H5VM.c in HDF5 before 2.2.0 lets a remote attacker cause an application crash and possibly execute arbitrary code with a crafted HDF5 file. When a dataset's unallocated chunks are read, H5D__fill_init() fills the fill-value buffer from datatype and dataspace metadata in the file. If that metadata is inconsistent with the buffer's allocated size, the write goes past the end of the buffer. The attacker can control the content written through the fill value stored in the file.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
The HDF Group · HDF5CVEs relacionadas — The HDF Group HDF5
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-92627MEDIUMHeap Use-After-Free in H5T__conv_f_fEPSS 0.2%CVE-2026-19028MEDIUMHDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds readEPSS 0.2%CVE-2026-19027MEDIUMHDF5 out-of-bounds heap read in N-Bit filter decompressionEPSS 0.2%CVE-2026-19026MEDIUMNbit filter NULL/short parameter-array dereferenceEPSS 0.2%CVE-2026-19025MEDIUMHDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank on dataset openEPSS 0.2%CVE-2026-19024HIGHHDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value MessageEPSS 0.2%
Referencias
https://github.com/HDFGroup/hdf5/pull/6529