Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94499.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94499
Upstream
  • CVE-2026-19028
Published
2026-08-06T00:16:53Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-19028 affecting package hdf5 1.14.6-4
Details

H5Z__filterfletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a sizet underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5checksumfletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by the h5ls or h5dump tools.

References

Affected packages

Azure Linux:3 / hdf5

Package

Name
hdf5
Purl
pkg:rpm/azure-linux/hdf5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.14.6-4

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94499.json"