Bug 2457327 (CVE-2026-29043) - CVE-2026-29043 HDF5: HDF5: Remote code execution and denial of service via heap buffer overflow in H5T__ref_mem_setnull
Summary: CVE-2026-29043 HDF5: HDF5: Remote code execution and denial of service via he...
Keywords:
Status: NEW
Alias: CVE-2026-29043
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-10 16:02 UTC by OSIDB Bzimport
Modified: 2026-04-13 10:59 UTC (History)
5 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-10 16:02:37 UTC
HDF5 is software for managing data. In 1.14.1-2 and earlier, an attacker who can control an h5 file parsed by HDF5 can trigger a write-based heap buffer overflow condition in the H5T__ref_mem_setnull method. This can lead to a denial-of-service condition, and potentially further issues such as remote code execution depending on the practical exploitability of the heap overflow against modern operating systems.


Note You need to log in before you can comment on or make changes to this bug.