What is CVE-2026-19023?
CVE-2026-19023 is an untrusted pointer dereference vulnerability in the render_bin_output function of the h5dump tool within HDF5. Affecting versions prior to 2.3.0, an attacker can cause a denial of service by using a variable-length string dataset with multiple elements dumped in binary mode, which corrupts the per-element stride calculation. Users should upgrade HDF5 to version 2.3.0 or later.
Azərbaycanca: CVE-2026-19023, HDF5 kitabxanasının h5dump alətində "render_bin_output" funksiyasında etibarsız göstərici (pointer) tətbiqidir. HDF5-in 2.3.0-dan əvvəlki versiyalarına təsir edir: hücumçu ikili rejimdə (binary mode) ötürülən dəyişən uzunluqlu sətir verilənlər dəsti ilə "per-element stride" hesablamasını pozaraq xidmət rəddi (denial of service) yarada bilər. İstifadəçilər HDF5-i ən azı 2.3.0 versiyasına yeniləməlidir.
FAQ2
How can one protect against CVE-2026-19023?
Users should upgrade the HDF5 library to version 2.3.0 or later.
What can an attacker achieve by exploiting CVE-2026-19023?
An attacker can cause a denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.