Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-19024— HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message

CVSS 8.2 · High EPSS 0.13% · P3

Possible ATT&CK Techniques 1AI

T1499 · Endpoint Denial of Service

Affected Version Matrix 1

VendorProductVersion RangeStatus
The HDF GroupHDF5<= 2.3.0affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-19024

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message
Source: CVE Program / CVE List V5
Vulnerability Description
NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field, which is not normalized to the library's "undefined" sentinel and reaches H5T_path_find with a NULL datatype.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5
Vulnerability Title
The HDF Group HDF5 异常处理不当漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
The HDF Group HDF5是The HDF Group组织的一款面向科学数据的分层存储格式。 The HDF Group HDF5 2.1.1之前版本存在异常处理不当漏洞,该漏洞源于H5Pget_fill_value函数存在空指针取消引用问题,具体原因为版本1或2填充值消息中“defined”标志与负大小字段同时设置,未标准化为库的“undefined”哨兵,并以NULL数据类型到达H5T_path_find,可能导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
The HDF GroupHDF5 <= 2.3.0 -

II. Public POCs for CVE-2026-19024

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 12305 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-19024

登录查看更多情报信息。

Vendor Advisories for CVE-2026-19024 (1)

Same Patch Batch · The HDF Group · 2026-08-05 · 6 CVEs total

CVE-2026-190276.9 MEDIUMHDF5 out-of-bounds heap read in N-Bit filter decompression
CVE-2026-190236.8 MEDIUMHDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datas
CVE-2026-190256.8 MEDIUMHDF5 divide-by-zero (SIGFPE) via mismatched chunk-layout dimensionality and dataspace rank
CVE-2026-190266.8 MEDIUMNbit filter NULL/short parameter-array dereference
CVE-2026-190286.8 MEDIUMHDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read

IV. Related Vulnerabilities

V. Comments for CVE-2026-19024

No comments yet


Leave a comment