Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26199

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If H5Iget_name is invoked on a group id with 0 for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if H5Iget_name is invoked in a way where size can be forced to zero, and there is important data before the name buffer.

A flaw was found in HDF5, a library used for managing large datasets. This vulnerability occurs when a specific function, H5Iget_name, is called with an invalid size parameter, leading to a buffer underflow. An attacker could exploit this by providing specially crafted input, potentially causing the application to crash or become unavailable, resulting in a denial of service (DoS).

Отчет

This Moderate vulnerability in HDF5 involves a buffer underflow in the H5Iget_name function, which can lead to a denial of service. Exploitation requires an attacker to provide specially crafted input that forces the size parameter to zero, a condition not commonly encountered in default Red Hat configurations, thus limiting the attack's practicality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AI Inference Serverrhaii/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/model-opt-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-cuda-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-neuron-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-rocm-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-spyre-rhel9Fix deferred
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cpu-rhel9Fix deferred
Red Hat AI Inference Serverrhaii/vllm-cuda-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-124
https://bugzilla.redhat.com/show_bug.cgi?id=2502848HDF5: HDF5: Denial of Service via buffer underflow in H5Iget_name

EPSS

Процентиль: 17%
0.00256
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
19 дней назад

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer.

CVSS3: 6.5
nvd
19 дней назад

HDF5 is a high-performance library and a file format specification that implements the HDF5 data model. If `H5Iget_name` is invoked on a group id with `0` for the size parameter, it will underflow when trying to place a null terminator in the buffer. This can occur if `H5Iget_name` is invoked in a way where `size` can be forced to zero, and there is important data before the `name` buffer.

msrc
18 дней назад

Buffer underflow in `H5Iget_name `/`H5G_get_name` if size is zero

CVSS3: 6.5
debian
19 дней назад

HDF5 is a high-performance library and a file format specification tha ...

EPSS

Процентиль: 17%
0.00256
Низкий

5.3 Medium

CVSS3

Уязвимость CVE-2026-26199