PT-2026-31703 · Hdf5+1 · Hdf5+1

Denandz

·

Published

2026-04-09

·

Updated

2026-05-12

·

CVE-2026-34734

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HDF5 versions 1.14.1-2 and earlier
Description HDF5 is software for managing data. A heap-use-after-free issue was identified in the h5dump helper utility. An attacker can trigger this by providing a malicious h5 file. The issue occurs because a freed object is referenced in a memmove call from H5T conv struct. The object was allocated by H5D typeinfo init phase3 and freed by H5D typeinfo term.
Recommendations Update to a version later than 1.14.1-2

Exploit

Fix

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2026-07255
CVE-2026-34734
ECHO-4587-2D95-FBA0

Affected Products

Hdf5
Red Os