Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17574

Опубликовано: 27 июл. 2026
Источник: redhat
CVSS3: 5

Описание

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

A flaw was found in HDF5. A local user can exploit this vulnerability by processing a specially crafted HDF5 file. This file, containing an attribute with an invalid variable-length datatype, can cause a NULL pointer dereference, leading to an application crash and resulting in a denial of service.

Отчет

This Moderate impact denial of service vulnerability in HDF5 can lead to an application crash when processing a specially crafted HDF5 file. This issue affects Red Hat products that utilize HDF5 for data handling, requiring user interaction to process the malicious file.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=2507552HDF5: HDF5: Denial of Service via crafted HDF5 file processing

5 Medium

CVSS3

Связанные уязвимости

ubuntu
21 день назад

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

nvd
21 день назад

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

debian
21 день назад

HDF5 contains a NULL pointer dereference vulnerability. Processing a c ...

github
21 день назад

HDF5 contains a NULL pointer dereference vulnerability. Processing a crafted HDF5 file containing an attribute with an invalid variable-length datatype type field may cause the application to crash when the attribute is read.

5 Medium

CVSS3

Уязвимость CVE-2026-17574