Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17573

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.

A flaw was found in the HDF5 library. A local user could exploit a double free vulnerability by processing a specially crafted HDF5 file with an oversized chunk size field using the h5repack tool. This could cause the application to unexpectedly terminate, leading to a denial of service.

Отчет

This Moderate severity flaw in the HDF5 library can lead to a denial of service. It requires a local attacker to trick a user into processing a specially crafted HDF5 file with the h5repack utility, which could cause the application to crash due to a double free vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-763
https://bugzilla.redhat.com/show_bug.cgi?id=2507553hdf5: HDF5 library: Denial of Service via crafted HDF5 file processing

EPSS

Процентиль: 2%
0.00117
Низкий

5 Medium

CVSS3

Связанные уязвимости

ubuntu
21 день назад

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.

nvd
21 день назад

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.

debian
21 день назад

A double free vulnerability was discovered in the HDF5 library. Proces ...

github
21 день назад

A double free vulnerability was discovered in the HDF5 library. Processing a crafted HDF5 file containing an oversized chunk size field via h5repack may cause the application to abort due to a double free.

EPSS

Процентиль: 2%
0.00117
Низкий

5 Medium

CVSS3