CVE-2026-19024: HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message
NULL pointer dereference in H5Pgetfillvalue in HDF5 before 2.1.1 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field, which is not normalized to the library's "undefined" sentinel and reaches H5Tpathfind with a NULL datatype.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HDF5to a version that resolves this vulnerability.Fixed in 2.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19024?
CVE-2026-19024 has a risk score of 23, indicating a high severity vulnerability.
How do I fix CVE-2026-19024?
To mitigate CVE-2026-19024, upgrade to HDF5 version 2.1.1 or later.
What is the impact of CVE-2026-19024?
CVE-2026-19024 may lead to a denial of service due to a NULL pointer dereference.
Which software is affected by CVE-2026-19024?
CVE-2026-19024 affects HDF Group HDF5 versions prior to 2.1.1.
What type of vulnerability is CVE-2026-19024?
CVE-2026-19024 is classified as a Null Pointer Dereference vulnerability.