CVE-2026-17572: HDF5 SOHM List Index Heap Buffer Overflow
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a nummessages count exceeding listmax, triggering out-of-bounds heap reads and writes in H5SMcachelistdeserialize and H5SMcachelistverifychksum.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-17572?
CVE-2026-17572 has a risk score of 33, indicating a potential for significant impact.
How do I fix CVE-2026-17572?
Updating to version 2.1.2 or later of HDF5 will resolve the vulnerability associated with CVE-2026-17572.
What type of vulnerability is CVE-2026-17572?
CVE-2026-17572 is classified as a heap-based buffer overflow vulnerability.
What effect can CVE-2026-17572 have on my system?
Exploitation of CVE-2026-17572 can lead to a denial of service by crashing the application.
Which software is affected by CVE-2026-17572?
CVE-2026-17572 affects all platforms running HDF Group HDF5 versions up to 2.1.1.