Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/HDFGroup/hdf5/issues/6487 |
|
Wed, 05 Aug 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 allows attackers to cause a denial of service via a dataset whose version 1 or 2 fill value message has the "defined" flag set together with a negative size field, which is not normalized to the library's "undefined" sentinel and reaches H5T_path_find with a NULL datatype. | |
| Title | HDF5 H5Pget_fill_value NULL Pointer Dereference via Malformed Fill Value Message | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: HDFG
Published:
Updated: 2026-08-05T22:14:29.792Z
Reserved: 2026-08-05T22:12:47.262Z
Link: CVE-2026-19024
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T23:30:04Z
-
CWE-476
NULL Pointer Dereference