Junglewise Threat Intelligence

CVE-2026-26200: HDFGroup HDF5 heap buffer overflow in H5T__conv_struct_opt

CVE-2026-26200 · Severity: high · CVSS 7.8 · Published 2026-02-19

Technologies: Hdfgroup Hdf5, Red Hat Enterprise Linux AI (RHEL AI) 3. Vendors: Hdfgroup, Red Hat.

Executive brief

HDF5 is a widely used library and file format for managing and storing large amounts of complex data. A security vulnerability has been identified where a specially crafted data file (.h5) can cause the software to crash or potentially allow an attacker to run unauthorized code. This risk is primarily present when a user is tricked into opening a malicious file or if an automated system processes untrusted data.

Technical details

A heap-based buffer overflow exists in HDF5 due to an incorrect calculation of buffer size in the H5T__conv_struct_opt method. The vulnerability is triggered when the library parses a maliciously crafted .h5 file, specifically through the h5dump utility or other components using the H5T conversion functions. An attacker can achieve an out-of-bounds write, leading to a denial-of-service (crash) or potentially arbitrary code execution. While the primary attack vector involves local user interaction (opening a file), server-side processes that automatically parse user-supplied HDF5 files are also at risk. The issue is addressed in version 1.14.4-2.

Affected products

  • HDFGroup HDF5 < 1.14.4-2
  • Red Hat Red Hat Enterprise Linux AI (RHEL AI) 3 affected

Timeline

  • 2026-02-14: advisory: GitHub advisory published by HDFGroup
  • 2026-02-19: disclosed: CVE-2026-26200 published
  • 2026-02-19: patched: Version 1.14.4-2 released to fix the issue

References

Related threats