Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19027

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 5.6

Описание

The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows attackers to cause an out-of-bounds heap read, and in constrained cases disclosure of adjacent heap memory into decompressed dataset values, via a crafted HDF5 file whose N-Bit filter parameters describe more decompressed data than the stored compressed chunk actually contains, triggered via H5Dread, e.g. by the h5ls or h5repack tools.

A flaw was found in HDF5, a widely used data management library. This vulnerability allows an attacker to craft a malicious HDF5 file that, when processed, can cause the application to read beyond its allocated memory. This out-of-bounds read could lead to the disclosure of sensitive information or result in a denial of service (DoS), making the application unavailable.

Отчет

A boundary validation flaw exists in the N-Bit decompression routines (H5Z__nbit_decompress_one_*) within the HDF5 library. When processing datasets via H5Dread(), the functions fail to bound the read index against the compressed buffer size. An attacker can exploit this by enticing a user or automated service to open a crafted HDF5 file with mismatched N-Bit filter parameters, causing a heap out-of-bounds read. This flaw primarily impacts system availability via application crashes, with a secondary risk of minor heap memory disclosure.

Меры по смягчению последствий

Do not open or process untrusted HDF5 files from unverified sources using tools or services linked against the HDF5 library. Enforce strict file-ingestion boundaries or access controls to prevent automated parsing of untrusted datasets.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3hdf5Affected
Red Hat Hardened Imageshdf5Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2511860hdf5: HDF5: Information disclosure and denial of service via crafted HDF5 file

5.6 Medium

CVSS3

Связанные уязвимости

ubuntu
11 дней назад

The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows attackers to cause an out-of-bounds heap read, and in constrained cases disclosure of adjacent heap memory into decompressed dataset values, via a crafted HDF5 file whose N-Bit filter parameters describe more decompressed data than the stored compressed chunk actually contains, triggered via H5Dread, e.g. by the h5ls or h5repack tools.

nvd
11 дней назад

The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows attackers to cause an out-of-bounds heap read, and in constrained cases disclosure of adjacent heap memory into decompressed dataset values, via a crafted HDF5 file whose N-Bit filter parameters describe more decompressed data than the stored compressed chunk actually contains, triggered via H5Dread, e.g. by the h5ls or h5repack tools.

msrc
10 дней назад

HDF5 out-of-bounds heap read in N-Bit filter decompression

debian
11 дней назад

The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, ...

github
11 дней назад

The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows attackers to cause an out-of-bounds heap read, and in constrained cases disclosure of adjacent heap memory into decompressed dataset values, via a crafted HDF5 file whose N-Bit filter parameters describe more decompressed data than the stored compressed chunk actually contains, triggered via H5Dread, e.g. by the h5ls or h5repack tools.

5.6 Medium

CVSS3