Medium severity5.5NVD Advisory· Published Apr 10, 2026· Updated Apr 16, 2026
CVE-2026-29043
CVE-2026-29043
Description
HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/HDFGroup/hdf5/security/advisories/GHSA-qm2m-5g5w-2277nvdExploitVendor Advisory
News mentions
0No linked articles in our index yet.