Description
H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 prior to 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.
Published: 2026-08-05
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

Within H5Z__filter_fletcher32, the code calculates the data length to checksum by subtracting four bytes for the trailing checksum from the input buffer size but does not verify that the buffer is at least four bytes. This size_t underflow permits a chunk smaller than four bytes to produce a very large length, causing an out‑of‑bounds read in the Fletcher32 checksum routine and leading the application to crash. The result is a denial of service when the library reads a malicious HDF5 file containing such a corrupted chunk.

Affected Systems

The HDF Group's HDF5 library, versions 2.3.0 and earlier, contain the vulnerable code. The issue was disclosed in 2026 and affects built‑in tools such as h5ls and h5dump as well as any software that uses this library to read HDF5 files.

Risk and Exploitability

With a CVSS score of 6.8, the vulnerability is considered moderate. The EPSS score is less than 1 percent and the issue is not listed in CISA's KEV catalog. An attacker can trigger the underflow by supplying a crafted HDF5 file that includes a Fletcher32‑filtered chunk of fewer than four bytes; reading the file with H5Dread, such as through h5ls or h5dump, will cause the out‑of‑bounds read and crash the application.

Generated by OpenCVE AI on October 7, 2026 at 08:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the HDF5 library to a version that contains the fix for the Fletcher32 filter (for example, by applying the patch introduced in pull request 6497).
  • Validate the size of Fletcher32‑filtered chunks before they are processed, ensuring each chunk is at least four bytes to prevent the out‑of‑bounds read.
  • Restrict the processing of untrusted HDF5 files or disable the Fletcher32 filter in environments where the library cannot be updated immediately.

Generated by OpenCVE AI on October 7, 2026 at 08:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Description H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools. H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 prior to 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.

Fri, 14 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Fri, 07 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Hdfgroup
Hdfgroup hdf5
Vendors & Products Hdfgroup
Hdfgroup hdf5

Thu, 06 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Description H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.
Title HDF5 integer underflow in Fletcher32 filter leads to massive out-of-bounds read
Weaknesses CWE-125
CWE-1284
CWE-190
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HDFG

Published:

Updated: 2026-10-06T20:32:52.600Z

Reserved: 2026-08-05T22:14:41.781Z

Link: CVE-2026-19028

cve-icon Vulnrichment

Updated: 2026-08-06T14:25:45.350Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-06T00:16:53.427

Modified: 2026-10-06T21:17:20.267

Link: CVE-2026-19028

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-05T23:15:09Z

Links: CVE-2026-19028 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T08:30:15Z

Weaknesses
  • CWE-125

    Out-of-bounds Read

  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-190

    Integer Overflow or Wraparound