What is CVE-2026-17574?
CVE-2026-17574 is a NULL pointer dereference vulnerability in the HDF5 library. Processing a specially crafted HDF5 file with an attribute containing an invalid variable-length datatype field may lead to an application crash when the attribute is read. Affected users should update HDF5 to the latest version and avoid opening untrusted files.
Azərbaycanca: CVE-2026-17574 HDF5 kitabxanasında NULL pointer dereference zəifliyidir. Xüsusi hazırlanmış HDF5 faylı emal edilərkən, etibarsız dəyişən uzunluqlu datatype sahəsi olan atribut oxunduqda tətbiqin çökməsinə səbəb ola bilər. Təsirə məruz qalan istifadəçilər HDF5-i ən son versiyaya yeniləməli və şübhəli faylları açmaqdan çəkinməlidir.
Related CVEs
link basis: same weakness class CWE-476
FAQ2
What type of issue is CVE-2026-17574 in the HDF5 library?
CVE-2026-17574 is a NULL pointer dereference vulnerability in the HDF5 library.
What should users do to protect against CVE-2026-17574?
Affected users should update HDF5 to the latest version and avoid opening untrusted files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.