What is CVE-2026-19027?
The decompression functions in H5Znbit.c within the HDF5 library through version 2.3.0 fail to bound the read index against the buffer size, leading to an out-of-bounds read vulnerability. This could allow an attacker to read sensitive information by crafting malicious files. Affected users should update to the latest version and avoid opening HDF5 files from untrusted sources.
Azərbaycanca: HDF5 kitabxanasının 2.3.0 və əvvəlki versiyalarında H5Znbit.c faylında yerləşən dekompressiya funksiyalarında oxuma indeksinin buffer ölçüsü ilə məhdudlaşdırılmaması səbəbindən out-of-bounds read zəifliyi mövcuddur. Bu, təcavüzkara xüsusi hazırlanmış fayllar vasitəsilə məxfi məlumatları oxumağa imkan verə bilər. Təsirə məruz qalan istifadəçilər kitabxananı ən son versiyaya yeniləməli və şübhəli mənbələrdən HDF5 fayllarını açmamalıdır.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which versions of the HDF5 library are affected by CVE-2026-19027?
The HDF5 library through version 2.3.0 is affected by this out-of-bounds read vulnerability.
What measures are recommended to protect against CVE-2026-19027?
Users are advised to update the HDF5 library to the latest version and avoid opening HDF5 files from untrusted sources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.