Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19028

Опубликовано: 05 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.

A flaw was found in HDF5. An attacker can craft a malicious HDF5 file with a specially designed Fletcher32-filtered chunk. When this file is processed, an integer underflow occurs due to insufficient size validation, leading to a massive out-of-bounds read. This vulnerability can cause the application to crash, resulting in a denial of service.

Отчет

An integer underflow vulnerability exists in HDF5's H5Z__filter_fletcher32() function within H5Zfletcher32.c. When reading dataset chunks via H5Dread(), the Fletcher32 filter subtracts a 4-byte checksum length from the buffer size without validating that the buffer is at least 4 bytes. An attacker can exploit this by enticing a user or service to process a crafted HDF5 file containing a sub-4-byte Fletcher32-filtered chunk, causing a size_t wraparound and massive out-of-bounds read in H5_checksum_fletcher32(). The primary impact of this flaw is an application crash leading to a denial of service.

Меры по смягчению последствий

Do not open or process untrusted HDF5 files from unverified sources using tools or services linked against the HDF5 library. Enforce file-ingestion boundaries or access controls to restrict automated parsing of untrusted datasets.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3hdf5Affected
Red Hat Hardened Imageshdf5Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2511855hdf5: HDF5: Denial of Service via integer underflow in Fletcher32 filter

EPSS

Процентиль: 3%
0.00127
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
11 дней назад

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.

nvd
11 дней назад

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.

msrc
10 дней назад

HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read

debian
11 дней назад

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 comput ...

github
11 дней назад

H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.

EPSS

Процентиль: 3%
0.00127
Низкий

5.5 Medium

CVSS3

Уязвимость CVE-2026-19028