Executive brief
HDF5 is a widely used library and file format for managing and storing large amounts of complex data. A security vulnerability has been identified where a specially crafted data file (.h5) can cause the software to crash or potentially allow an attacker to run unauthorized code. This risk is primarily present when a user is tricked into opening a malicious file or if an automated system processes untrusted data.
Technical details
A heap-based buffer overflow exists in HDF5 due to an incorrect calculation of buffer size in the H5T__conv_struct_opt method. The vulnerability is triggered when the library parses a maliciously crafted .h5 file, specifically through the h5dump utility or other components using the H5T conversion functions. An attacker can achieve an out-of-bounds write, leading to a denial-of-service (crash) or potentially arbitrary code execution. While the primary attack vector involves local user interaction (opening a file), server-side processes that automatically parse user-supplied HDF5 files are also at risk. The issue is addressed in version 1.14.4-2.
Affected products
- HDFGroup HDF5 < 1.14.4-2
- Red Hat Red Hat Enterprise Linux AI (RHEL AI) 3 affected
Timeline
- 2026-02-14: advisory: GitHub advisory published by HDFGroup
- 2026-02-19: disclosed: CVE-2026-26200 published
- 2026-02-19: patched: Version 1.14.4-2 released to fix the issue