CVE-2026-17572: Hdfgroup HDF5
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.
Affected products
- Hdfgroup HDF5: before 2.2.0 (fixed in 2.2.0)
Published 2026-07-27. Last modified 2026-08-18.