Bug 2511860 (CVE-2026-19027) - CVE-2026-19027 hdf5: HDF5: Information disclosure and denial of service via crafted HDF5 file
Summary: CVE-2026-19027 hdf5: HDF5: Information disclosure and denial of service via c...
Keywords:
Status: NEW
Alias: CVE-2026-19027
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2516019 2516020
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-05 23:21 UTC by OSIDB Bzimport
Modified: 2026-08-14 13:13 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-05 23:21:36 UTC
The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows attackers to cause an out-of-bounds heap read, and in constrained cases disclosure of adjacent heap memory into decompressed dataset values, via a crafted HDF5 file whose N-Bit filter parameters describe more decompressed data than the stored compressed chunk actually contains, triggered via H5Dread, e.g. by the h5ls or h5repack tools.


Note You need to log in before you can comment on or make changes to this bug.