CVE-2026-17574: NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag
Published Jul 27, 2026
·Updated
HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.
Affected Software
1 affected component
HDF5
Event History
Jul 27, 2026
CVE Published
via MITRE·03:12 PM
Data Sourced
via MITRE·03:12 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-17574?
CVE-2026-17574 has a medium severity rating of 5.2 on the CVSS scale.
2
How do I fix CVE-2026-17574?
To fix CVE-2026-17574, users should update to the latest version of HDF5 that addresses this vulnerability.
3
What does CVE-2026-17574 affect?
CVE-2026-17574 affects the HDF5 software, specifically when processing crafted HDF5 files with invalid variable-length datatype type tags.
4
What is a NULL pointer dereference in the context of CVE-2026-17574?
In the context of CVE-2026-17574, a NULL pointer dereference occurs when the application crashes due to an invalid attribute being read.
5
When was CVE-2026-17574 published?
CVE-2026-17574 was published on July 27, 2026.