Junglewise Threat Intelligence

CVE-2026-26199: HDFGroup HDF5 buffer underflow in H5Iget_name

CVE-2026-26199 · Severity: info · CVSS 5.9 · Published 2026-07-20

Technologies: Hdfgroup Hdf5. Vendors: Hdfgroup.

Executive brief

HDF5 is a high-performance library used for managing and storing large amounts of complex data. A flaw in how the library handles certain name-retrieval requests could allow a crash or memory corruption if a specific parameter is set to zero. This could potentially lead to service instability or application crashes in environments where data processing inputs are not strictly controlled.

Technical details

A buffer underwrite (CWE-124) exists in the HDF5 library within the H5Iget_name and H5G_get_name functions. When these functions are invoked with a size parameter of 0, the library attempts to place a null terminator in the buffer, leading to a memory underflow. This vulnerability was discovered via fuzzing and requires a specific precondition where an attacker can influence the size parameter passed to the API. An exploit can result in a denial of service (application crash) or corruption of data stored immediately before the intended buffer in memory. The issue is reported to be fixed in version 2.1.0.

Affected products

  • HDFGroup hdf5 <= 1.14.6

Timeline

  • 2026-06-26: advisory: GitHub Security Advisory published
  • 2026-07-20: disclosed: CVE published to NVD

References