CVE-2017-17509: Hdfgroup HDF5
High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.
In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.
Affected products
- Hdfgroup HDF5: version 1.10.1 only
Published 2017-12-11. Last modified 2026-06-17.