CVE-2026-17573: Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field
Published Jul 27, 2026
·Updated
A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.
Affected Software
1 affected component
HDF Group HDF5
Event History
Jul 27, 2026
CVE Published
via MITRE·03:11 PM
Data Sourced
via MITRE·03:11 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-17573?
The severity of CVE-2026-17573 is rated as medium with a CVSS score of 4.0.
2
How do I fix CVE-2026-17573?
To fix CVE-2026-17573, update the HDF5 library to the latest version where the vulnerability has been addressed.
3
What kind of vulnerability is CVE-2026-17573?
CVE-2026-17573 is a double free vulnerability that affects the HDF5 library.
4
What impact does CVE-2026-17573 have?
CVE-2026-17573 can cause applications to abort when processing crafted HDF5 files with oversized chunk size fields.
5
Which software is affected by CVE-2026-17573?
CVE-2026-17573 affects the HDF Group HDF5 library.