CVE-2017-17509: Hdfgroup HDF5

High severity, CVSS 8.8. EPSS: 1.5% chance of exploitation in the next 30 days.

In HDF5 1.10.1, there is an out of bounds write vulnerability in the function H5G__ent_decode_vec in H5Gcache.c in libhdf5.a. For example, h5dump would crash or possibly have unspecified other impact someone opens a crafted hdf5 file.

Affected products

Published 2017-12-11. Last modified 2026-06-17.