CVE-2026-17572

Heap-based buffer overflow in the SOHM list-index deserialization code in HDF5 through 2.1.1 on all platforms allows attackers to cause a denial of service (crash) via a crafted HDF5 file whose shared-message list index declares a num_messages count exceeding list_max, triggering out-of-bounds heap reads and writes in H5SM__cache_list_deserialize and H5SM__cache_list_verify_chksum.
CVSS

No CVSS.

Configurations

No configuration.

History

27 Jul 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-27 16:17

Updated : 2026-07-30 20:11


NVD link : CVE-2026-17572

Mitre link : CVE-2026-17572

CVE.ORG link : CVE-2026-17572


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read

CWE-787

Out-of-bounds Write