Impact
Within H5Z__filter_fletcher32, the code calculates the data length to checksum by subtracting four bytes for the trailing checksum from the input buffer size but does not verify that the buffer is at least four bytes. This size_t underflow permits a chunk smaller than four bytes to produce a very large length, causing an out‑of‑bounds read in the Fletcher32 checksum routine and leading the application to crash. The result is a denial of service when the library reads a malicious HDF5 file containing such a corrupted chunk.
Affected Systems
The HDF Group's HDF5 library, versions 2.3.0 and earlier, contain the vulnerable code. The issue was disclosed in 2026 and affects built‑in tools such as h5ls and h5dump as well as any software that uses this library to read HDF5 files.
Risk and Exploitability
With a CVSS score of 6.8, the vulnerability is considered moderate. The EPSS score is less than 1 percent and the issue is not listed in CISA's KEV catalog. An attacker can trigger the underflow by supplying a crafted HDF5 file that includes a Fletcher32‑filtered chunk of fewer than four bytes; reading the file with H5Dread, such as through h5ls or h5dump, will cause the out‑of‑bounds read and crash the application.
OpenCVE Enrichment