CVE-2026-26200: HDF5 Affected by H5T__conv_struct_opt Heap Buffer Overflow
HDF5 is software for managing data. Prior to version 1.14.4-2, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems. Real-world exploitability of this issue in terms of remote-code execution is currently unknown. Version 1.14.4-2 fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
HDF5to a version that resolves this vulnerability.Fixed in 1.14.4-2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26200?
CVE-2026-26200 has a critical severity rating due to the potential for remote code execution and denial of service.
How do I fix CVE-2026-26200?
To fix CVE-2026-26200, upgrade to HDF5 version 1.14.4-2 or later.
What vulnerabilities does CVE-2026-26200 introduce?
CVE-2026-26200 can introduce a write-based heap buffer overflow that may lead to denial of service or remote code execution.
Who is affected by CVE-2026-26200?
The vulnerability affects users operating HDF5 versions prior to 1.14.4-2.
What can an attacker achieve by exploiting CVE-2026-26200?
An attacker exploiting CVE-2026-26200 can potentially cause a denial of service and may execute arbitrary code.