Description
A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An attacker who can supply a crafted HDF5 file containing a specially constructed compound datatype can trigger the use-after-free when the file is parsed by an application that reads the affected dataset, such as h5dump. This can result in a crash and, depending on heap layout and allocator behavior, may be exploitable for further memory corruption up to remote code execution.
Published: 2026-09-16
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution (potential)
Action: Apply Patch
AI Analysis

Impact

A heap-use-after-free flaw exists in the H5T__conv_f_f function of HDF5, triggered when converting compound datatypes that contain floating-point members during a dataset read. The routine frees a temporary buffer allocated with calloc() and later reads from it, leading to a crash and, depending on heap layout and allocator behavior, potential memory corruption and remote code execution.

Affected Systems

The flaw affects The HDF Group's HDF5 library versions earlier than 1.14.2. Any application that reads such datasets in a vulnerable file, such as the h5dump utility, is susceptible.

Risk and Exploitability

The CVSS score of 4.6 positions the vulnerability at a moderate level. The EPSS score of less than 1% suggests current exploitation activity is low, and the feature is not listed in CISA's KEV catalog. However, the attack vector is straightforward: an attacker crafts an HDF5 file with a specially constructed compound datatype, and a victim application opens the file to read the dataset. The lack of required authentication and the reliance on parsing user-supplied data make the exploitation path simple, though achieving full remote code execution would also depend on the underlying heap state and allocator behavior.

Generated by OpenCVE AI on September 18, 2026 at 06:29 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade HDF5 to version 1.14.2 or later (the vulnerability is fixed in that release).
  • Restrict or sandbox the usage of applications that open HDF5 files (e.g., run h5dump in a protected environment).
  • Avoid loading or processing untrusted HDF5 files whenever possible.

Generated by OpenCVE AI on September 18, 2026 at 06:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Hdfgroup
Hdfgroup hdf5
Vendors & Products Hdfgroup
Hdfgroup hdf5

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
Description A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 2.3.0. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An attacker who can supply a crafted HDF5 file containing a specially constructed compound datatype can trigger the use-after-free when the file is parsed by an application that reads the affected dataset, such as h5dump. This can result in a crash and, depending on heap layout and allocator behavior, may be exploitable for further memory corruption up to remote code execution. A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 1.14.2. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An attacker who can supply a crafted HDF5 file containing a specially constructed compound datatype can trigger the use-after-free when the file is parsed by an application that reads the affected dataset, such as h5dump. This can result in a crash and, depending on heap layout and allocator behavior, may be exploitable for further memory corruption up to remote code execution.

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description A heap-use-after-free vulnerability exists in H5T__conv_f_f() in src/H5Tconv.c in HDF5 before 2.3.0. When converting a compound datatype containing floating-point members during a dataset read, a temporary buffer allocated with calloc() is freed and subsequently read from within the same conversion routine. An attacker who can supply a crafted HDF5 file containing a specially constructed compound datatype can trigger the use-after-free when the file is parsed by an application that reads the affected dataset, such as h5dump. This can result in a crash and, depending on heap layout and allocator behavior, may be exploitable for further memory corruption up to remote code execution.
Title Heap Use-After-Free in H5T__conv_f_f
Weaknesses CWE-416
References
Metrics cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: HDFG

Published:

Updated: 2026-09-17T17:36:14.708Z

Reserved: 2026-09-16T15:14:38.985Z

Link: CVE-2026-92627

cve-icon Vulnrichment

Updated: 2026-09-17T17:36:11.594Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T16:17:23.993

Modified: 2026-09-18T19:34:36.657

Link: CVE-2026-92627

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-16T15:16:54Z

Links: CVE-2026-92627 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:51:36Z

Weaknesses