Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-26199

Опубликовано: 20 июл. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If H5Iget_name is invoked on a group id with 0 for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if H5Iget_name is invoked in a way where size can be forced to zero, and there is important data before the name buffer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hdfgroup:hdf5:*:*:*:*:*:*:*:*
Версия до 2.1.0 (исключая)

EPSS

Процентиль: 17%
0.00256
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-124

Связанные уязвимости

CVSS3: 6.5
ubuntu
19 дней назад

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer.

CVSS3: 5.3
redhat
19 дней назад

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer.

msrc
18 дней назад

Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero

CVSS3: 6.5
debian
19 дней назад

HDF5 is a high-performance library and a file format specification tha ...

EPSS

Процентиль: 17%
0.00256
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-124