在 HDF5 2.1.1 及以下版本中,所有平台上的 SOHM(Shared Object Header Message)列表索引反序列化代码存在基于堆的缓冲区溢出漏洞。攻击者可通过构造特殊的 HDF5 文件,使共享消息列表索引中声明的 计数值超过 ,从而在 和 函数中触发越界堆读写,导致拒绝服务(程序崩溃)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| The HDF Group | HDF5 | <= 2.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| The HDF Group | HDF5 | <= 2.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17574 | 5.2 MEDIUM | NULL Pointer Dereference in HDF5 via Invalid Variable-Length Datatype Type Tag |
| CVE-2026-17573 | 4.0 MEDIUM | Double Free in H5D__chunk_copy() in HDF5 via a Crafted Chunk-Index Size Field |
No comments yet