What is CVE-2026-19024?
This vulnerability is a NULL pointer dereference in the `H5Pget_fill_value` function in HDF5 versions before 2.3.0. An attacker can cause a denial of service by using a specially crafted dataset. Users should upgrade to HDF5 version 2.3.0 or later.
Azərbaycanca: Bu boşluq HDF5 kitabxanasının 2.3.0-dan əvvəlki versiyalarında `H5Pget_fill_value` funksiyasında aşkarlanmış NULL pointer dereference zəifliyidir. Təcavüzkar xüsusi hazırlanmış dataset vasitəsilə xidmət rəddi (denial of service) yarada bilər. İstifadəçilərə HDF5 kitabxanasını 2.3.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-476
FAQ2
What type of vulnerability is CVE-2026-19024 and in which HDF5 function is it located?
This vulnerability is a NULL pointer dereference in the `H5Pget_fill_value` function in HDF5 versions before 2.3.0.
What happens if CVE-2026-19024 is exploited and how should users protect themselves?
An attacker can cause a denial of service by using a specially crafted dataset. Users should upgrade to HDF5 version 2.3.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.