CVE-2026-17572: Hdfgroup HDF5

Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.

Affected products

  • Hdfgroup HDF5: before 2.2.0 (fixed in 2.2.0)

Published 2026-07-27. Last modified 2026-08-18.