Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/HDFGroup/hdf5/issues/6486 |
|
Wed, 05 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.1.1 allows attackers to cause a denial of service via a variable-length string dataset with more than one element dumped in binary mode, which corrupts the per-element stride calculation and causes subsequent elements to be read from a misaligned offset and dereferenced as a pointer. | |
| Title | HDF5 h5dump Untrusted Pointer Dereference in Binary Output of Variable-Length String Datasets | |
| Weaknesses | CWE-822 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HDFG
Published:
Updated: 2026-08-05T22:13:45.859Z
Reserved: 2026-08-05T22:12:46.385Z
Link: CVE-2026-19023
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T23:30:04Z
-
CWE-822
Untrusted Pointer Dereference