Description
A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5 through 2.2.0 lets an attacker cause a denial of service (application crash) with a crafted HDF5 file. When the stored minimum bits equal the full precision of the datatype, the decoder copies d_nelmts * size bytes from the compressed chunk without checking that the chunk holds that many bytes. Both values come from attacker-controlled scale-offset filter parameters in the dataset's filter pipeline message.
Published: 2026-10-06
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A heap-based buffer over-read occurs in the scale-offset filter routine of the HDF5 library when decoding a compressed chunk. The vulnerability triggers an application crash if the stored minimum bits equal the datatype precision, causing the decoder to copy too many bytes from the chunk without bounds checking. This results in a denial of service by exhausting memory or corrupting critical data structures.

Affected Systems

The weakness affects the HDF Group's HDF5 implementation up to and including version 2.2.0. Any system or application that loads HDF5 files containing the scale‑offset filter can be impacted, regardless of the operating system or hardware platform.

Risk and Exploitability

The CVSS score of 6.8 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by presenting a maliciously crafted HDF5 file to any application that processes it, so the likely attack vector is local file usage or remote delivery if the file is transmitted over network and then decoded. The lack of mandatory boundary checks means the exploit requires only read access to the target file.

Generated by OpenCVE AI on October 7, 2026 at 00:18 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HDF5 to a version newer than 2.2.0 which contains the mitigation for the over‑read bug
  • If an upgrade is not timely, configure your application to reject or ignore the scale‑offset filter before decoding the file
  • Add pre‑processing checks that verify the compressed chunk size matches the declared number of elements multiplied by element size
  • Limit the use of unknown or untrusted HDF5 files to a sandboxed environment where a crash cannot affect the rest of the system

Generated by OpenCVE AI on October 7, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Tue, 06 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Description A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5 through 2.2.0 lets a remote attacker cause a denial of service (application crash) with a crafted HDF5 file. When the stored minimum bits equal the full precision of the datatype, the decoder copies d_nelmts * size bytes from the compressed chunk without checking that the chunk is that large. Both values come from attacker-controlled scale-offset filter parameters in the dataset's filter pipeline message. A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5 through 2.2.0 lets an attacker cause a denial of service (application crash) with a crafted HDF5 file. When the stored minimum bits equal the full precision of the datatype, the decoder copies d_nelmts * size bytes from the compressed chunk without checking that the chunk holds that many bytes. Both values come from attacker-controlled scale-offset filter parameters in the dataset's filter pipeline message.

Tue, 06 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Description A heap-based buffer over-read in H5Z__filter_scaleoffset() in src/H5Zscaleoffset.c in HDF5 through 2.2.0 lets a remote attacker cause a denial of service (application crash) with a crafted HDF5 file. When the stored minimum bits equal the full precision of the datatype, the decoder copies d_nelmts * size bytes from the compressed chunk without checking that the chunk is that large. Both values come from attacker-controlled scale-offset filter parameters in the dataset's filter pipeline message.
Title HDF5 scale-offset filter heap buffer over-read via crafted chunk
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: HDFG

Published:

Updated: 2026-10-06T20:56:27.850Z

Reserved: 2026-08-05T22:14:42.476Z

Link: CVE-2026-19029

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T21:17:20.410

Modified: 2026-10-06T21:17:20.410

Link: CVE-2026-19029

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T00:30:08Z

Weaknesses