← Back

CVE-2026-29043

nvd nist
Published: Apr 10, 2026Modified: Apr 16, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: security-advisories@github.com (Secondary)

Description

HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems.

Affected (1)

Products: Hdfgroup: Hdf5
1 product
Hdf5
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.14.1-2

References (1)

Source: security-advisories@github.com
ExploitVendor Advisory

Timeline

No history available yet.