Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29043

Опубликовано: 10 апр. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems.

A flaw was found in HDF5, a software for managing data. An attacker who can control a specially crafted HDF5 (.h5) file can trigger a write-based heap buffer overflow in the H5T__ref_mem_setnull method when the file is parsed. This vulnerability can lead to a denial-of-service condition, and potentially allow for remote code execution depending on the exploitability of the heap overflow against modern operating systems.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3hdf5Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2457327HDF5: HDF5: Remote code execution and denial of service via heap buffer overflow in H5T__ref_mem_setnull

EPSS

Процентиль: 12%
0.00213
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
4 месяца назад

HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems.

CVSS3: 5.5
nvd
4 месяца назад

HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems.

CVSS3: 5.5
debian
4 месяца назад

HDF5 is software for managing data. In 1.14.1-2 and earlier, an attack ...

EPSS

Процентиль: 12%
0.00213
Низкий

5.5 Medium

CVSS3